{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T14:08:30.935","vulnerabilities":[{"cve":{"id":"CVE-2024-6672","sourceIdentifier":"security@progress.com","published":"2024-08-29T22:15:05.953","lastModified":"2026-06-17T08:18:27.500","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password."},{"lang":"es","value":"En las versiones de WhatsUp Gold lanzadas antes de 2024.0.0, una vulnerabilidad de inyección SQL permite que un atacante autenticado con pocos privilegios logre una escalada de privilegios modificando la contraseña de un usuario privilegiado."}],"affected":[{"source":"security@progress.com","affectedData":[{"vendor":"Progress Software Corporation","product":"WhatsUp Gold","defaultStatus":"affected","modules":["API Endpoint"],"platforms":["Windows"],"versions":[{"version":"2023.1.0","lessThan":"2024.0.0","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"progress","product":"whatsupgold","defaultStatus":"affected","cpes":["cpe:2.3:a:progress:whatsupgold:*:*:*:*:*:*:*:*"],"versions":[{"version":"2023.1.0","lessThan":"2024.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T13:44:33.392630Z","id":"CVE-2024-6672","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@progress.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*","versionEndExcluding":"24.0","matchCriteriaId":"F88DF254-746E-41F3-A2CA-0DC0B5C49837"}]}]}],"references":[{"url":"https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024","source":"security@progress.com","tags":["Vendor Advisory"]},{"url":"https://www.progress.com/network-monitoring","source":"security@progress.com","tags":["Product"]}]}}]}