← Back to CVE List

CVE-2024-5018

Published: 2024-06-25T21:16Z
Last Modified: 2024-11-21T09:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory . > MITRE Terms of Use apply – see LICENSE‑MITRE.txt