In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days