Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
XML External Entity Processing Information Disclosure
Vulnerability Description
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Vulnerability Title
Progress Software Telerik Report Server 安全漏洞
Vulnerability Description
Progress Software Telerik Report Server是Progress Software公司的一种企业级报表管理和分发解决方案。 Progress Software Telerik Report Server 2024 Q1版本及之前版本存在安全漏洞。攻击者利用该漏洞通过 XML 外部实体处理读取系统文件。
CVSS Information
N/A
Vulnerability Type
N/A