Vulnerabilities > Progress > Telerik Reporting > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-09 CVE-2024-7293 Weak Password Requirements vulnerability in Progress Telerik Reporting
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
network
low complexity
progress CWE-521
8.8
2024-10-09 CVE-2024-7840 Command Injection vulnerability in Progress Telerik Reporting 12.0.18.125
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
local
low complexity
progress CWE-77
7.8
2024-10-09 CVE-2024-8014 Unsafe Reflection vulnerability in Progress Telerik Reporting 12.0.18.125
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
network
low complexity
progress CWE-470
8.8
2024-10-09 CVE-2024-8048 Unsafe Reflection vulnerability in Progress Telerik Reporting 12.0.18.125
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
local
low complexity
progress CWE-470
7.8
2024-01-31 CVE-2024-0832 Unspecified vulnerability in Progress Telerik Reporting
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
local
low complexity
progress
7.8