Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xq4v-69gf-r78f

Опубликовано: 31 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

EPSS

Процентиль: 71%
0.00674
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 лет назад

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

EPSS

Процентиль: 71%
0.00674
Низкий

7.8 High

CVSS3

Дефекты

CWE-269