Unrated severityNVD Advisory· Published Oct 9, 2024· Updated Nov 3, 2025
Improper neutralization special element in hyperlinks
CVE-2024-7840
Description
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2024 Q3 (18.2.24.924)
- Range: 18.2.24.806
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.