logo
Home/CVEs/CVE-2024-6670/

CVE-2024-6670 - Progress WhatsUp Gold SQL Injection Vulnerability

Project:Progress

Product:WhatsUp Gold

Date Added:2024-09-16Due Date:2024-10-07

Vulnerability Name

Progress WhatsUp Gold SQL Injection Vulnerability

Description

Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024

https://nvd.nist.gov/vuln/detail/CVE-2024-6670

Related News Articles

Progress urges admins to patch critical WhatsUp Gold bugs ASAPSeptember 27, 2024

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical FlawSeptember 13, 2024

Hackers targeting WhatsUp Gold with public exploit since AugustSeptember 13, 2024