Show filters
55 Total Results
Displaying 31-40 of 55
Sort by:
Attacker Value
Unknown
CVE-2023-6595
Disclosure Date: December 14, 2023 (last updated October 16, 2024)
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
0
Attacker Value
Unknown
CVE-2023-6368
Disclosure Date: December 14, 2023 (last updated October 16, 2024)
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.
0
Attacker Value
Unknown
CVE-2023-6367
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.
If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
0
Attacker Value
Unknown
CVE-2023-6366
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Alert Center.
If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
0
Attacker Value
Unknown
CVE-2023-6365
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a device group.
If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
0
Attacker Value
Unknown
CVE-2023-6364
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a dashboard component.
If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
0
Attacker Value
Unknown
CVE-2023-35759
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
0
Attacker Value
Unknown
CVE-2022-42711
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
0
Attacker Value
Unknown
CVE-2022-29848
Disclosure Date: May 11, 2022 (last updated August 28, 2024)
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the WhatsUp Gold system.
0
Attacker Value
Unknown
CVE-2022-29847
Disclosure Date: May 11, 2022 (last updated August 28, 2024)
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.
0