Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-4358


In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.


Published

2024-05-29T15:16:06.477

Last Modified

2025-01-27T21:43:05.630

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-290
  • Type: Primary
    CWE-290

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application telerik report_server_2024 ≤ 10.0.24.305 Yes

References