Command Injection Vulnerability in Progress Telerik UI for WinForms
CVE-2024-7679

7.8HIGH

Key Information:

Vendor

Telerik

Vendor
CVE Published:
25 September 2024

What is CVE-2024-7679?

A command injection vulnerability exists in Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924) due to improper neutralization of hyperlink elements. This flaw can potentially enable unauthorized commands to be executed in the context of the affected application, posing significant security risks to users and systems utilizing older versions. It is essential for organizations to evaluate and update their installations to the latest version to mitigate any associated threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.