CVE-2015-8261 is a critical SQL injection vulnerability affecting Ipswitch WhatsUp Gold versions prior to 16.4. It allows remote, unauthenticated attackers to execute arbitrary SQL commands by sending a specially crafted SOAP request that exploits improper validation of serialized XML objects within the DroneDeleteOldMeasurements implementation. This vulnerability has a CVSS score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability compromise. While not listed on CISA KEV, an ExploitDB entry exists for remote code execution, suggesting potential for active exploitation, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.3CPE matchmatch criteria | cpe:2.3:a:progress:whatsup_gold:16.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.