← Back to browse · API

CVE-2024-4884

Severity
CRITICAL
CVSS
9.8
EPSS
0.24306
Risk score
47.71
CISA KEV
No
PoC
No
Published
2024-06-25
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-44454, GHSA-2JFG-R68G-P4GM
Products
Progress Software Corporation:WhatsUp Gold 2023.1.0 <2023.1.3
Sources
euvd EUVD-2024-44454

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

References