Impact
The vulnerability allows a privileged attacker to create a LogToFile action that writes an arbitrary file extension into the IIS web root, enabling the attacker to place or overwrite files on the server. This arbitrary file write can be leveraged to gain persistence, execute code, or tamper with configuration files, thereby compromising confidentiality, integrity, and availability of the monitoring platform. The weakness aligns with CWE-22, CWE-434, and CWE-73, reflecting insufficient path validation and unchecked file handling.
Affected Systems
Progress Software Corporation’s WhatsUp Gold versions earlier than 26.0.2 are affected. All releases prior to the 26.0.2 patch, including 26.0.1 and below, are potentially vulnerable when the LogToFile action handler is enabled. Systems running these older iterations without the update are at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, because the flaw requires privileged access to the web interface to create the LogToFile action, only authenticated users with sufficient rights can exploit it; the attack vector is likely local or authenticated remote. Once an attacker writes malicious code to the server, successful exploitation could allow arbitrary code execution or denial of service.
OpenCVE Enrichment