CVE-2024-6670: Progress WhatsUp Gold SQL Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-16. EPSS: 93% chance of exploitation in the next 30 days.

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Affected products

  • Progress WhatsUp Gold: before 24.0 (fixed in 24.0)

Published 2024-08-29. Last modified 2026-06-17.