First published: Wed Sep 25 2024(Updated: )
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik UI for WPF | <2024.3.924 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7575 is classified as a medium severity vulnerability due to the potential for command injection attacks.
To fix CVE-2024-7575, upgrade Telerik UI for WPF to version 2024 Q3 (2024.3.924) or later.
CVE-2024-7575 affects all versions of Telerik UI for WPF prior to version 2024 Q3 (2024.3.924).
Using an affected version of Telerik UI for WPF post-disclosure poses security risks due to the command injection vulnerability.
CVE-2024-7575 enables command injection attacks through improper handling of hyperlink elements.