Low-Privileged User Can Escalate Privileges to Admin via SSRF and IAC Vulnerabilities in WhatsUp Gold Before 2023.1.3
CVE-2024-5015
What is CVE-2024-5015?
A security vulnerability has been identified in WhatsUp Gold, where an authenticated Server Side Request Forgery (SSRF) vulnerability exists in the Session Controller component, specifically within Wug.UI.Areas.Wug.Controllers.SessionControler.Update. This flaw allows low privileged users to exploit the vulnerability in conjunction with an improper access control weakness. The exploitation can lead to unauthorized privilege escalation, enabling a low level user to gain administrative access within the application. It is essential for users of WhatsUp Gold to upgrade to version 2023.1.3 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WhatsUp Gold Windows 2023.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved