In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Telerik ui For Wpf
|
|
CPEs | cpe:2.3:a:telerik:ui_for_wpf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Telerik ui For Wpf
|
Wed, 25 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Telerik
Telerik ui For Winforms |
|
CPEs | cpe:2.3:a:telerik:ui_for_winforms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Telerik
Telerik ui For Winforms |
|
Metrics |
ssvc
|
Wed, 25 Sep 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements. | |
Title | Improper neutralization special element in hyperlinks | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2024-09-25T13:53:01.102Z
Updated: 2024-09-25T14:22:18.409Z
Reserved: 2024-08-10T17:47:30.861Z
Link: CVE-2024-7679
Vulnrichment
Updated: 2024-09-25T14:21:22.018Z
NVD
Status : Analyzed
Published: 2024-09-25T14:15:06.180
Modified: 2024-10-01T17:16:17.397
Link: CVE-2024-7679
Redhat
No data.