Impact
Progress Software Telerik Report Server versions prior to 12.2.26.1007 are vulnerable to a stored cross‑site scripting flaw. An authenticated report author can embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user opens the malicious report and the navigation link is activated, the attacker’s script runs in the context of the web report viewer and can perform actions with the victim’s elevated privileges. Consequently, an attacker can gain administrative access by executing privileged operations through a victim user’s session.
Affected Systems
All deployments of Progress Software Telerik Report Server that use a version earlier than 12.2.26.1007 are affected. The vulnerability arises from the shared reporting engine component of the product.
Risk and Exploitability
The CVSS score of 8.9 indicates high severity, and the lack of an EPSS score suggests the exploitation probability is not quantified but should be considered significant in a multi‑user environment. The vulnerability can be exploited by a legitimate user with report‑authoring rights, requiring only that another user view the report to trigger the script. As the script executes in the origin of the viewer, it can carry out actions in the victim’s account, including administrative functions, thereby enabling privilege escalation.
OpenCVE Enrichment