QID 731289
Date Published: 2024-03-26
QID 731289: Progress Telerik Report Server Insecure Deserialization Vulnerability
Progress Telerik Report Server is a server-based reporting platform that provides comprehensive reports management. It provides a centralized storage for the reports and various ways to organize and preview them.
Progress Telerik Report Server is vulnerable to a remote code execution attack through an insecure deserialization vulnerability.
Affected Versions:
Report Server 10.0.24.130 and prior versions.
Patched Version:
Report Server 10.0.24.305 and later versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Progress Telerik Report Server by sending an HTTP GET request to the 'Account/Login' endpoint and extracting the version from the response received.
Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to execute arbitrary code, leading to complete system compromise.
- Progress Security Advisory -
docs.telerik.com/report-server/knowledge-base/deserialization-vulnerability-cve-2024-1800
CVEs related to QID 731289
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Progress Security Advisory |
|