CVE-2018-8938: Progress WhatsUp Gold
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold server.
Affected products
- Progress WhatsUp Gold: before 18.0 (fixed in 18.0)
Published 2018-05-01. Last modified 2026-06-17.