Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-11628


In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.


Published

2025-02-12T17:15:22.067

Last Modified

2025-06-27T19:18:38.750

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1321

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress kendo_ui_for_vue < 6.1.0 Yes

References