CVE-2024-12629
EUVD-2024-5100912.02.2025, 16:15
In ProgressĀ® TelerikĀ® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| progress | kendoreact | 3.5.0 ≤ 𝑥 < 9.4.0 |
𝑥
= Vulnerable software versions