CVE-2024-6670

CVE Published 2024-08-29
Related CWE(s) CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Related Vendor(s) progress
Related Product(s) whatsup_gold
Exploitation Reported (CISA KEV) 2024-09-16
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References