PT-2024-32277 · Ipswitch · Whatsup Gold

CVE-2024-46907

·

Published

2024-09-27

·

Updated

2024-12-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WhatsUp Gold versions prior to 2024.0.1
Description A SQL Injection issue allows an authenticated low-privileged user, with at least Report Viewer permissions, to escalate privileges to the admin account. This issue can be exploited by a user with limited access, potentially leading to significant security breaches.
Recommendations For versions prior to 2024.0.1, update to version 2024.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetFilterCriteria function until a patch is available. Additionally, limiting privileges for low-privileged users and closely monitoring system activity can help minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46907
ZDI-24-1686

Affected Products

Whatsup Gold