Home

Description

In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.

PUBLISHED Reserved 2024-05-06 | Published 2024-05-14 | Updated 2024-08-01 | Assigner ProgressSoftware




MEDIUM: 4.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
affected

2023.1.0 (semver) before 2023.1.2
affected

Credits

Abdessamad Lahlali of Trend Micro. finder

References

www.progress.com/network-monitoring product

community.progress.com/.../Announcing-WhatsUp-Gold-v2023-1-2 vendor-advisory

cve.org (CVE-2024-4561)

nvd.nist.gov (CVE-2024-4561)

Download JSON