Vulnerability Details CVE-2022-29845
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.582
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-29845
-
cpe:2.3:a:progress:whatsup_gold:21.1.0
-
cpe:2.3:a:progress:whatsup_gold:21.1.1
-
cpe:2.3:a:progress:whatsup_gold:22.0.0