📦 Whatsup Gold

by Progress

🔍 What is Whatsup Gold?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-12106

CRITICAL CVSS 9.4 Dec 31, 2024

This vulnerability allows unauthenticated attackers to configure LDAP settings in WhatsUp Gold, potentially enabling them to redirect authentication to malicious LDAP servers or disrupt legitimate aut...

CVE-2024-46909

CRITICAL CVSS 9.8 Dec 2, 2024

CVE-2024-46909 is a critical remote code execution vulnerability in WhatsUp Gold network monitoring software. Unauthenticated attackers can exploit this to execute arbitrary code with service account ...

CVE-2024-8785

CRITICAL CVSS 9.8 Dec 2, 2024

This vulnerability allows remote unauthenticated attackers to modify registry values in WhatsUp Gold installations, potentially enabling system compromise. It affects WhatsUp Gold versions before 2024...

CVE-2024-7763

CRITICAL CVSS 9.8 Oct 24, 2024

WhatsUp Gold versions before 2024.0.0 contain an authentication bypass vulnerability that allows attackers to obtain encrypted user credentials without proper authentication. This affects all organiza...

CVE-2024-6670

CRITICAL CVSS 9.8 Aug 29, 2024

An unauthenticated SQL injection vulnerability in WhatsUp Gold allows attackers to retrieve encrypted user passwords. This affects all WhatsUp Gold versions before 2024.0.0. Organizations using vulner...

CVE-2024-4883

CRITICAL CVSS 9.8 Jun 25, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on WhatsUp Gold systems through the NmApi.exe component. Attackers can achieve remote code execution as a service a...

CVE-2024-4885

CRITICAL CVSS 9.8 Jun 25, 2024

An unauthenticated remote code execution vulnerability in Progress WhatsUp Gold allows attackers to execute arbitrary commands with IIS application pool privileges. This affects WhatsUp Gold versions ...

CVE-2024-46905

HIGH CVSS 8.8 Dec 2, 2024

A SQL injection vulnerability in WhatsUp Gold versions before 2024.0.1 allows authenticated users with Network Manager permissions to escalate privileges to admin accounts. This affects organizations ...

CVE-2024-46906

HIGH CVSS 8.8 Dec 2, 2024

A SQL injection vulnerability in WhatsUp Gold allows authenticated users with at least Report Viewer permissions to escalate privileges to admin accounts. This affects WhatsUp Gold versions before 202...

CVE-2024-46907

HIGH CVSS 8.8 Dec 2, 2024

A SQL injection vulnerability in WhatsUp Gold allows authenticated low-privileged users (with at least Report Viewer permissions) to escalate privileges to admin accounts. This affects all WhatsUp Gol...

CVE-2024-46908

HIGH CVSS 8.8 Dec 2, 2024

A SQL injection vulnerability in WhatsUp Gold allows authenticated users with Report Viewer permissions to escalate privileges to admin accounts. This affects WhatsUp Gold versions before 2024.0.1. At...

CVE-2024-6672

HIGH CVSS 8.8 Aug 29, 2024

This SQL injection vulnerability in WhatsUp Gold allows authenticated low-privileged users to modify privileged user passwords, leading to privilege escalation. It affects all WhatsUp Gold versions be...

CVE-2024-5013

HIGH CVSS 7.5 Jun 25, 2024

An unauthenticated Denial of Service vulnerability in WhatsUp Gold allows attackers to force the application into the SetAdminPassword installation step, making it inaccessible. This affects all Whats...

CVE-2024-5015

HIGH CVSS 7.1 Jun 25, 2024

This vulnerability allows authenticated low-privileged users in WhatsUp Gold to perform server-side request forgery (SSRF) attacks. By chaining this SSRF with an improper access control vulnerability,...

CVE-2024-5009

HIGH CVSS 8.4 Jun 25, 2024

This vulnerability allows local attackers to modify the administrator password in WhatsUp Gold through improper access control in the SetAdminPassword function. It affects WhatsUp Gold versions before...

CVE-2024-5011

HIGH CVSS 7.5 Jun 25, 2024

An unauthenticated attacker can send specially crafted HTTP requests to the TestController Chart functionality in WhatsUp Gold, causing uncontrolled resource consumption and denial of service. This af...

CVE-2023-6595

HIGH CVSS 7.5 Dec 14, 2023

CVE-2023-6595 is an authentication bypass vulnerability in WhatsUp Gold network monitoring software. Unauthenticated attackers can access an API endpoint to enumerate credential information stored in ...

CVE-2023-6366

HIGH CVSS 7.6 Dec 14, 2023

This stored XSS vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into the Alert Center. When users interact with the crafted payload, the attacker can execute arbitrary co...

CVE-2023-6364

HIGH CVSS 7.6 Dec 14, 2023

A stored cross-site scripting (XSS) vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into dashboard components. When users interact with these components, the attacker can...

CVE-2022-29847

HIGH CVSS 7.5 May 11, 2022

This vulnerability allows unauthenticated attackers to invoke an API transaction that relays encrypted WhatsUp Gold user credentials to arbitrary hosts. It affects Progress Ipswitch WhatsUp Gold versi...

CVE-2025-2572

MEDIUM CVSS 5.6 Apr 14, 2025

An unauthenticated database manipulation vulnerability in WhatsUp Gold allows attackers to modify the WrlsMacAddressGroup table without credentials. This affects all WhatsUp Gold installations running...

CVE-2024-12105

MEDIUM CVSS 6.5 Dec 31, 2024

This vulnerability allows authenticated users of WhatsUp Gold to craft HTTP requests that can disclose sensitive information. It affects all WhatsUp Gold versions before 2024.0.2. The vulnerability st...

CVE-2024-5017

MEDIUM CVSS 6.5 Jun 25, 2024

This path traversal vulnerability in WhatsUp Gold allows unauthenticated attackers to access files outside the intended directory via specially crafted HTTP requests to AppProfileImport. It affects Wh...

CVE-2024-5019

MEDIUM CVSS 5.3 Jun 25, 2024

This vulnerability allows unauthenticated attackers to read arbitrary files on WhatsUp Gold servers with IIS application pool privileges. It affects WhatsUp Gold versions before 2023.1.3, potentially ...

CVE-2024-4562

MEDIUM CVSS 5.4 May 14, 2024

This SSRF vulnerability in WhatsUp Gold allows authenticated users to make unauthorized HTTP requests through the HTTP Monitoring functionality. Attackers could potentially access internal systems or ...