ZDI-24-561: Progress Software Telerik Reporting Register Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Progress Software Telerik Reporting. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-4358.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-561?
The severity of ZDI-24-561 is rated 9.8 on the CVSS scale, indicating it is a critical vulnerability.
What type of vulnerability is ZDI-24-561?
ZDI-24-561 is an authentication bypass vulnerability that allows remote attackers to exploit affected installations.
How do I fix ZDI-24-561?
To fix ZDI-24-561, it is recommended to update to the latest version of Progress Software Telerik Reporting as per vendor guidance.
Who is affected by ZDI-24-561?
Any installations of Progress Software Telerik Reporting are potentially affected by ZDI-24-561.
Is authentication required to exploit ZDI-24-561?
No, authentication is not required to exploit the ZDI-24-561 vulnerability.