← Back to browse · API

CVE-2024-46906

Severity
HIGH
CVSS
8.8
EPSS
0.40584
Risk score
49.4
CISA KEV
No
PoC
No
Published
2024-12-02
Modified
2024-12-02
First seen
2026-08-07
Aliases
EUVD-2024-42183, GHSA-JW3V-5RHP-24PG
Products
Progress Software Corporation:WhatsUp Gold 2023.1.0 <2024.0.1
Sources
euvd EUVD-2024-42183

Description

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

References