← Back to browse · API

CVE-2024-6671

Severity
CRITICAL
CVSS
9.8
EPSS
0.14886
Risk score
44.41
CISA KEV
No
PoC
No
Published
2024-08-29
Modified
2024-09-25
First seen
2026-08-07
Aliases
EUVD-2024-47722, GHSA-HFXC-WFWP-6PQV
Products
Progress Software Corporation:WhatsUp Gold 2023.1.0 <2024.0.0
Sources
euvd EUVD-2024-47722

Description

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

References