In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-25 21:16
Updated : 2024-06-26 12:44
NVD link : CVE-2024-5015
Mitre link : CVE-2024-5015
CVE.ORG link : CVE-2024-5015
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)