在 Telerik® Report Server 12.2.26.1007 之前的 In Progress® 版本中,共享报表引擎存在一个存储型跨站脚本(XSS)漏洞。已认证的报表作者可以在报表导航操作或 HTML 文本框链接中嵌入 javascript: 或 vbscript: URL。当其他用户查看该恶意报表并触发嵌入的导航时,攻击者控制的脚本将在 Web 报表查看器的上下文中执行。在多人使用的 Report Server 部署环境中,此漏洞可导致权限提升,攻击者可以利用高权限用户(包括管理员)的已认证会话执行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Telerik Report Server | 0 ~ 12.2.26.1007 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet