CVE-2024-12251: Improper neutralization special element in hyperlinks
Published Feb 12, 2025
·Updated
In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
Affected Software
2 affected components
Telerik UI for WinUI<3.0.0
Progress Telerik UI for WinUI>=2.0.0<3.0.0
Event History
Feb 12, 2025
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12251?
CVE-2024-12251 has been classified as a high severity vulnerability due to the potential for command injection attacks.
2
How do I fix CVE-2024-12251?
To fix CVE-2024-12251, upgrade Telerik UI for WinUI to version 3.0.0 or later.
3
What versions of Telerik UI for WinUI are affected by CVE-2024-12251?
Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0) are affected by CVE-2024-12251.
4
What is the nature of the vulnerability in CVE-2024-12251?
CVE-2024-12251 involves a command injection attack due to improper neutralization of hyperlink elements.
5
Is CVE-2024-12251 easy to exploit?
Yes, CVE-2024-12251 is relatively easy to exploit, making it critical to apply the necessary updates.