CISA Known Exploited Vulnerability (KEV)
Progress WhatsUp Gold SQL Injection Vulnerability
September 16, 2024
October 7, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-89 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) |