PT-2024-32276 · Ipswitch · Whatsup Gold

Published

2024-09-27

·

Updated

2024-12-12

·

CVE-2024-46906

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WhatsUp Gold versions prior to 2024.0.1
Description A SQL Injection vulnerability in WhatsUp Gold allows an authenticated low-privileged user with at least Report Viewer permissions to achieve privilege escalation to the admin account. This issue enables a low-level user to gain administrative access.
Recommendations For versions prior to 2024.0.1, update to version 2024.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetSqlWhereClause function until a patch is available. Additionally, limit the use of Report Viewer permissions to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46906
ZDI-24-1684

Affected Products

Whatsup Gold