In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .
Metrics
Affected Vendors & Products
References
History
Wed, 21 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Progress
Progress whatsup Gold |
|
CPEs | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | |
Vendors & Products |
Progress
Progress whatsup Gold |
MITRE
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2024-06-25T20:27:11.395Z
Updated: 2024-08-01T20:55:10.444Z
Reserved: 2024-05-16T15:59:56.888Z
Link: CVE-2024-5018
Vulnrichment
Updated: 2024-08-01T20:55:10.444Z
NVD
Status : Modified
Published: 2024-06-25T21:16:01.543
Modified: 2024-11-21T09:46:47.587
Link: CVE-2024-5018
Redhat
No data.