CVE-2024-6671: Progress WhatsUp Gold

Critical severity, CVSS 9.8. EPSS: 19% chance of exploitation in the next 30 days.

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Affected products

  • Progress WhatsUp Gold: from 23.1.0, before 24.0 (fixed in 24.0)

Published 2024-08-29. Last modified 2026-06-17.