← Vulnerability feed

Vulnerability record · CVE-2017-9140 · published 22 May 2017

CVE-2017-9140: Progress telerik reporting cross-site scripting vulnerability

Progress · Telerik Reporting

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

6.1 CVSS 3.0 Medium EPSS 9.7% · top 4.6% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
9.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9140 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6096Progress telerik reporting vulnerabilityIn Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type reso…EPSS 0.86%8.8CVE-2024-7293Progress telerik reporting weak password requirements vulnerabilityIn Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requir…EPSS 0.33%8.8CVE-2024-8014Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure t…EPSS 0.62%8.8CVE-2024-1856Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…EPSS 1.1%8.6CVE-2024-4202Progress telerik reporting code injection vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner…EPSS 0.27%7.8CVE-2024-8048Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expres…EPSS 0.22%7.8CVE-2024-7840Progress telerik reporting command injection vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype…EPSS 0.66%7.8CVE-2024-4200Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2017-9140), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.