Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2024-1856
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-1801
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-0832
Disclosure Date: January 31, 2024 (last updated February 10, 2024)
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
0
Attacker Value
Unknown
CVE-2017-9140
Disclosure Date: May 22, 2017 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.
0