An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2024-05-15T16:58:31.306Z
Updated: 2024-06-04T17:54:31.326Z
Reserved: 2024-04-30T17:34:36.505Z
Link: CVE-2024-4357
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-05-15T17:15:15.783
Modified: 2024-05-15T18:35:11.453
Link: CVE-2024-4357
JSON object: View
Redhat Information
No data.
CWE