Beveiligingsadvies

CVE-2024-5018

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-25 20:27:11
Laatst bijgewerkt 2024-08-01 20:55:10
Toegewezen door ProgressSoftware
CVSS-score 5.3
Status PUBLISHED

Beschrijving

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .