CyberICT

CVE-2024-4885

Progress · Published June 25, 2024

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

Affected Products

  • Whatsup Gold < 23.1.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H