← Back to CVE List

CVE-2024-5015

Published: 2024-06-25T21:16Z
Last Modified: 2024-11-21T09:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt