CVE-2024-4561

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
14/05/2024
Last modified:
09/12/2024

Description

<br /> In WhatsUp Gold versions released before 2023.1.2 , <br /> <br /> a blind SSRF vulnerability exists in Whatsup Gold&amp;#39;s FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* 23.1.2 (excluding)