Assigner | ProgressSoftware |
Reserved | 2024-05-06 |
Published | 2024-05-14 |
Updated | 2024-06-04 |
Description
In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
2023.1.0 before 2023.1.2
Credits
Abdessamad Lahlali of Trend Micro.
References
https://www.progress.com/network-monitoring
https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2