Description
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46290 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory . |
References
History
Wed, 21 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress whatsup Gold |
|
| CPEs | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Progress
Progress whatsup Gold |
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2024-08-01T20:55:10.444Z
Reserved: 2024-05-16T15:59:56.888Z
Link: CVE-2024-5018
Updated: 2024-08-01T20:55:10.444Z
Status : Modified
Published: 2024-06-25T21:16:01.543
Modified: 2024-11-21T09:46:47.587
Link: CVE-2024-5018
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD