Home

Description

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

PUBLISHED Reserved 2024-12-03 | Published 2024-12-31 | Updated 2025-01-08 | Assigner ProgressSoftware




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
affected

2023.1.0 (semver) before 2024.0.2
affected

Credits

Marcin 'Icewall' Noga of Cisco Talos finder

References

www.talosintelligence.com/...ability_reports/TALOS-2024-2089

www.progress.com/network-monitoring

cve.org (CVE-2024-12105)

nvd.nist.gov (CVE-2024-12105)

Download JSON