#VU95446 Improper access control in WhatsUp Gold - CVE-2024-5009
Published: August 7, 2024 / Updated: October 11, 2024
WhatsUp Gold
Progress Software Corporation
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the implementation of SetAdminPassword method. A local attacker can bypass implemented security restrictions and modify admin's password.