Progress Telerik Report Server是美国Progress公司的一种企业级报表管理和分发解决方案。 Progress Telerik Report Server 2025 Q1版本之前存在安全漏洞,该漏洞源于当使用较旧的.NET Framework实现时,服务代理进程和应用程序主机进程之间的非敏感信息通信通过未加密的隧道进行,该隧道可能会受到本地网络流量嗅探。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Telerik Report Server | 1.0.0 ~ 2025 Q1 (11.0.25.211) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-11343 | 8.3 HIGH | Telerik Document Processing Path Traversal |
| CVE-2024-12251 | 7.8 HIGH | Improper neutralization special element in hyperlinks |
| CVE-2025-0332 | 7.8 HIGH | Progress UI for WinForms decompression path traversal vulnerability |
| CVE-2024-11629 | 7.1 HIGH | Telerik Document Processing RTF Export of Arbitrary File Path |
| CVE-2024-12629 | 4.1 MEDIUM | Prototype Pollution in Progress® Telerik® KendoReact |
| CVE-2024-11628 | 4.1 MEDIUM | Prototype Pollution in Progress® Telerik® Kendo UI for Vue |
No comments yet