Description
In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
2023.1.0 (semver) before 2023.1.2
Credits
Abdessamad Lahlali of Trend Micro.
References
www.progress.com/network-monitoring
community.progress.com/.../Announcing-WhatsUp-Gold-v2023-1-2