Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
18.2.24.806 (custom) before 18.2.24.924
affected
Description
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
Problem types
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Product status
18.2.24.806 (custom) before 18.2.24.924
Credits
Markus Wulftange with CODE WHITE GmbH.
References
security.netapp.com/advisory/ntap-20250425-0004/
docs.telerik.com/...cure-expression-evaluation-cve-2024-8048