Impact
The vulnerability allows a privileged attacker to write arbitrary files to a location that is directly served by the web server on the host running WhatsUp Gold. Because the files can be placed in a web‑accessible directory, an attacker could upload web shells, malicious scripts, or defacement pages that would execute when accessed, potentially leading to remote code execution or data exposure. The weakness is identified as improper file permissions and improper ownership controls, reflected in CWE-276 and CWE-732. This flaw does not automatically give the attacker network‑wide access but does allow exploitation of the local host if the attacker can gain administrative or privileged privileges on the server.
Affected Systems
All installations of Progress Software Corporation's WhatsUp Gold version 26.0.0 or earlier are affected. The vulnerability was documented for releases prior to version 26.0.2, and no later releases contain the fix.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The vulnerability requires a privileged attacker; therefore local or legitimate administrative access to the host is the inferred attack vector. While the flaw does not directly provide remote code execution from outside the host, uploading files to a web‑accessible directory opens the door to web‑based attacks once the files are exploited. The risk is moderate to high if privileged attacker access is possible or if the system is exposed to potential privilege abuse.
OpenCVE Enrichment