Vulnerabilities > CVE-2024-8048 - Unsafe Reflection vulnerability in Progress Telerik Reporting 12.0.18.125

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
progress
CWE-470

Summary

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

Vulnerable Configurations

Part Description Count
Application
Progress
1