GHSA-j337-6rqp-7m54MediumCVSS 6.8
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile...
🔗 CVE IDs covered (1)
📋 Description
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-65939
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2026
- https://docs.progress.com/bundle/whatsupgold-release-notes-26-0/page/WhatsUp-Gold-2026.0-Release-Notes.html
- https://www.progress.com/network-monitoring
- https://github.com/advisories/GHSA-j337-6rqp-7m54