CVE-2024-46906

Publication date

2024-12-02 14:44:08

Family

ProgressSoftware

State

PUBLISHED

Description

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.