Lucene search

K
nvd[email protected]NVD:CVE-2024-5019
HistoryJun 25, 2024 - 9:16 p.m.

CVE-2024-5019

2024-06-2521:16:01
CWE-22
web.nvd.nist.gov
7
whatsup gold
arbitrary file read
vulnerability
iisapppool\nmconsole privileges

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

46.8%

In WhatsUp Gold versions released before 2023.1.3,

an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. ThisΒ vulnerability allows reading of any file with iisapppool\NmConsole privileges.

Affected configurations

Nvd
Node
progresswhatsup_goldRange<23.1.3
VendorProductVersionCPE
progresswhatsup_gold*cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

46.8%

Related for NVD:CVE-2024-5019