CVE-2024-6670 is an unauthenticated SQL injection vulnerability in Progress WhatsUp Gold versions before 2024.0.0. The PerformanceMonitorErrorLogDao.HasErrors() implementation incorporates the requester-controlled classId value into a SQL query through string formatting without sanitization. The flaw permits database-query manipulation. An exploitation chain can use a separately unauthenticated product function that encrypts attacker-selected values with installation-specific cryptographic material, then use SQL injection to replace the administrator password value and authenticate as that administrator.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module targeting a SQL injection vulnerability (CVE-2024-6670) in Progress WhatsUp Gold versions prior to 24.0.0. The module allows an attacker to reset the password of an existing user (default: admin) to a value of their choosing by exploiting a SQL injection in the web interface. The exploit works by chaining several HTTP requests to specific endpoints, first retrieving the application version, then manipulating password values via SQL injection, and finally authenticating as the compromised user. The module is operational and provides a working attack chain, including credential storage and login verification. The code is written in Ruby and is structured as a standard Metasploit module, making it easy to use within the Metasploit framework. No hardcoded IPs or domains are present; all endpoints are relative to the target's base URI.
This repository contains a working exploit for CVE-2024-6670, a SQL injection authentication bypass vulnerability in Progress Software WhatsUp Gold. The main file, CVE-2024-6670.py, is a Python script that automates the exploitation process. It takes a target URL and a new password as arguments. The exploit works by first using a remote primitive to encrypt the desired new password, then leveraging a SQL injection vulnerability in the /NmConsole/Platform/PerformanceMonitorErrors/HasErrors endpoint to exfiltrate the encrypted admin password and update it in the database. The script then allows the attacker to log in as the admin user with the new password. The README provides usage instructions, references, and mitigation advice. The exploit is operational and provides full administrative access to the attacker on a vulnerable instance. The endpoints targeted are all under the /NmConsole/ path, and the attack is performed over HTTPS. The repository is well-structured, with clear documentation and a single exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.