Логотип exploitDog
bind:CVE-2024-5015
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-5015

Количество 2

Количество 2

nvd логотип

CVE-2024-5015

больше 1 года назад

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-mx99-9j8j-frc2

больше 1 года назад

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-5015

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-mx99-9j8j-frc2

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу