First published: Mon May 22 2017(Updated: )
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik Reporting | <11.0.17.406 | |
Progress Sitefinity CMS | >=4.2<=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9140 is classified as medium due to the potential for XSS attacks.
To fix CVE-2017-9140, upgrade Telerik Reporting to version 11.0.17.406 or later.
CVE-2017-9140 is a cross-site scripting (XSS) vulnerability.
CVE-2017-9140 affects Telerik Reporting for ASP.NET WebForms and Sitefinity CMS versions prior to the specified patches.
Yes, CVE-2017-9140 can be exploited remotely by injecting arbitrary web scripts or HTML.