CVE-2024-7575: Improper neutralization special element in hyperlinks
Published Sep 25, 2024
·Updated
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Affected Software
1 affected component
Telerik UI for WPF<2024.3.924
Event History
Sep 25, 2024
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7575?
CVE-2024-7575 is classified as a medium severity vulnerability due to the potential for command injection attacks.
2
How do I fix CVE-2024-7575?
To fix CVE-2024-7575, upgrade Telerik UI for WPF to version 2024 Q3 (2024.3.924) or later.
3
What products are affected by CVE-2024-7575?
CVE-2024-7575 affects all versions of Telerik UI for WPF prior to version 2024 Q3 (2024.3.924).
4
Can I still use an affected version of Telerik UI for WPF after CVE-2024-7575 is disclosed?
Using an affected version of Telerik UI for WPF post-disclosure poses security risks due to the command injection vulnerability.
5
What type of attack is possible with CVE-2024-7575?
CVE-2024-7575 enables command injection attacks through improper handling of hyperlink elements.