Impact
The vulnerability is a stored XSS flaw that allows an authenticated attacker to bypass frontend controls and insert persistent script content into the WhatsUp Gold web interface. This can alter page content, steal session cookies or execute arbitrary JavaScript in users’ browsers. The flaw is a classic CWE‑79 input validation weakness and requires valid credentials to exploit.
Affected Systems
The affected product is Progress Software Corporation’s WhatsUp Gold. All releases prior to version 26.0.2 (including any 2026.0.x before the patch) are vulnerable. Users must confirm that their deployment is running a supported secured version.
Risk and Exploitability
With a CVSS score of 8, this issue is considered high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an attacker who has authenticated to the web UI and can submit malicious payloads. Once injected, the script runs in the context of any user who views the affected page, potentially leading to session hijacking or broader compromise of the monitoring infrastructure.
OpenCVE Enrichment