PT-2024-32278 · Ipswitch · Whatsup Gold

Published

2024-09-27

·

Updated

2024-12-12

·

CVE-2024-46908

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WhatsUp Gold versions prior to 2024.0.1
Description A SQL Injection vulnerability allows an authenticated low-privileged user with at least Report Viewer permissions to achieve privilege escalation to the admin account.
Recommendations For versions prior to 2024.0.1, update to version 2024.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the GetFilterCriteria function until a patch is available. Restrict low-privileged users' access to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-46908
ZDI-24-1687

Affected Products

Whatsup Gold