Unrated severityNVD Advisory· Published May 15, 2024· Updated Aug 1, 2024
XML External Entity Processing Information Disclosure
CVE-2024-4357
Description
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
Affected products
2- Range: <=10.0.24.305
- Progress Software/Telerik Report Serverv5Range: 1.0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024-4357mitrevendor-advisory
News mentions
0No linked articles in our index yet.