Executive brief
A SQL injection vulnerability in Progress WhatsUp Gold allows an unauthenticated remote attacker to retrieve encrypted user passwords. This issue is particularly impactful in configurations with a single user, potentially leading to full account compromise.
Affected products
- Progress Software Corporation WhatsUp Gold versions released before 2024.0.0
Timeline
- 2024-08-29: disclosed: Initial disclosure by Progress Software Corporation
- 2024-09-16: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog
- 2024-09-16: exploited: Reported as exploited in the wild