Security Advisory

CVE-2024-5008

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-25 19:57:16
Last updated 2024-08-01 20:55:10
Assigner ProgressSoftware
State PUBLISHED

Description

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.