CVE-2024-46906
largeAuthenticated SQL Injection Privilege Escalation in Progress WhatsUp Gold
CVE-2024-46906 is a SQL injection flaw (CWE-89) in Progress WhatsUp Gold versions released before 2024.0.1. An attacker who already holds an account with at least Report Viewer permissions can send crafted input over the network to the monitoring application's database layer, allowing low-complexity exploitation with no user interaction. Successful abuse escalates the low-privileged user to the admin account, granting full control over the WhatsUp Gold console with high impact to confidentiality, integrity, and availability. Any organization running an unpatched WhatsUp Gold release prior to 2024.0.1 is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 40.4% (99th percentile) indicates a high probability of exploitation within 30 days; the fix shipped in WhatsUp Gold 2024.0.1 alongside a batch of other WhatsUp Gold patches from Progress.
What to do: Upgrade to WhatsUp Gold 2024.0.1 or later, which also addresses the other recently patched WhatsUp Gold flaws. Until patched, limit and review accounts holding Report Viewer or higher permissions, and monitor the WhatsUp Gold server for anomalous database queries or unexpected admin account activity. Check your installed version and confirm the 2024.0.1 update is applied, since exploitation risk is rated high (EPSS 40.4%) even though exploitation has not yet been confirmed.
| Progress WhatsUp Gold | all versions released before 2024.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
- Vendors
- progress
- Products
- whatsup gold
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H