← Vulnerability feed

Vulnerability record · CVE-2024-4202 · published 15 May 2024

CVE-2024-4202: Progress telerik reporting code injection vulnerability

Progress · Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.

8.6 CVSS 3.1 High EPSS 0.27% · top 82.7% CWE-94 · Code injection
8.6CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4202 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6096Progress telerik reporting vulnerabilityIn Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type reso…EPSS 0.86%8.8CVE-2024-7293Progress telerik reporting weak password requirements vulnerabilityIn Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requir…EPSS 0.33%8.8CVE-2024-8014Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure t…EPSS 0.62%8.8CVE-2024-1856Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…EPSS 1.1%7.8CVE-2024-8048Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expres…EPSS 0.22%7.8CVE-2024-7840Progress telerik reporting command injection vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype…EPSS 0.66%7.8CVE-2024-4200Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins…EPSS 0.30%7.8CVE-2024-1801Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insec…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2024-4202), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.