ZeroHour

CVE-2024-4884

CVSS 3.1
9.8 critical
EPSS
24%p98
Published
()
Modified
Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

Vendors
progress
Products
whatsup gold
Weakness
CWE-77, CWE-78, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news