CVE-2024-7679: Improper neutralization special element in hyperlinks
Published Sep 25, 2024
·Updated
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Affected Software
1 affected component
Telerik UI for WPF<2024.3.924
Event History
Sep 25, 2024
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7679?
CVE-2024-7679 is classified as a high severity vulnerability due to its potential for command injection attacks.
2
How can I fix CVE-2024-7679?
To mitigate CVE-2024-7679, update your Telerik UI for WinForms to version 2024 Q3 (2024.3.924) or later.
3
What types of applications are affected by CVE-2024-7679?
CVE-2024-7679 affects applications using Telerik UI for WinForms versions prior to 2024 Q3.
4
What is a command injection attack in the context of CVE-2024-7679?
In the context of CVE-2024-7679, a command injection attack allows an attacker to execute arbitrary commands on the host operating system.
5
How do I verify if my software is affected by CVE-2024-7679?
You can verify if your software is affected by CVE-2024-7679 by checking the version of Telerik UI for WinForms you have deployed.