← Back to browse · API

CVE-2024-6670

Severity
CRITICAL
CVSS
9.8
EPSS
0.94661
Risk score
58.13
CISA KEV
Yes
PoC
No
Published
2024-08-29
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-48017, GHSA-X5HW-48MF-CQ3M
Products
Progress Software Corporation:WhatsUp Gold 2023.1.0 <2024.0.0, Progress:WhatsUp Gold
Sources
cisa.gov CVE-2024-6670
euvd EUVD-2024-48017

Description

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

References