📦

telerik_reporting

Vendor: progress

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 5 Remote Access
Total CVEs 31 Total Indexed
Avg. EPSS 0.63% Exploit Prob.
Latest CVE CVE-2024-6097 Feb 12

Security Vulnerability Index

Page 1 / 4
5.3 CVSS

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

EPSS: 0.08%
7.8 CVSS

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

EPSS: 0.03%
8.8 CVSS

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

EPSS: 0.32%
7.8 CVSS

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

EPSS: 0.31%
7.5 CVSS

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.

EPSS: 0.30%
7.5 CVSS

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

EPSS: 0.19%
8.8 CVSS

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

EPSS: 0.19%
6.5 CVSS

An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.

EPSS: 1.54%
7.7 CVSS

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.

EPSS: 0.07%
7.7 CVSS
CVE-2024-4200
RCE Exploit Found

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

EPSS: 0.04%