← Vulnerability feed

Vulnerability record · CVE-2024-7840 · published 9 October 2024

CVE-2024-7840: Progress telerik reporting command injection vulnerability

Progress · Telerik Reporting

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

7.8 CVSS 3.1 High EPSS 0.66% · top 50.5% CWE-77 · Command injection
7.8CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6096Progress telerik reporting vulnerabilityIn Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type reso…EPSS 0.86%8.8CVE-2024-7293Progress telerik reporting weak password requirements vulnerabilityIn Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requir…EPSS 0.33%8.8CVE-2024-8014Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure t…EPSS 0.62%8.8CVE-2024-1856Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…EPSS 1.1%8.6CVE-2024-4202Progress telerik reporting code injection vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner…EPSS 0.27%7.8CVE-2024-8048Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expres…EPSS 0.22%7.8CVE-2024-4200Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins…EPSS 0.30%7.8CVE-2024-1801Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insec…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2024-7840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.