CVE-2024-4357
15.05.2024, 17:15
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.Enginsight
Vendor | Product | Version |
---|---|---|
progress_software | telerik_report_server | 10.0.24.514 < 𝑥 < 10.0.24.514 |
progress | telerik_reporting | 𝑥 < 10.1.24.514 |
𝑥
= Vulnerable software versions