Loading HuntDB...

GHSA-3325-26ch-q5p3

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.

Related CVEs

Key Information

GHSA ID
GHSA-3325-26ch-q5p3
Published
June 25, 2024 9:31 PM
Last Modified
August 21, 2024 3:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.