Description
In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.
Problem types
CWE-269 Improper Privilege Management
Product status
2023.1.0 before 2023.1.3
Credits
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) working with Trend Micro Zero Day Initiative
References
www.progress.com/network-monitoring
community.progress.com/...p-Gold-Security-Bulletin-June-2024