In ProgressĀ® TelerikĀ® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
References
Link | Resource |
---|---|
https://docs.telerik.com/report-server/knowledge-base/improper-restriction-of-excessive-login-attempts-cve-2024-7292 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-10-09 15:15
Updated : 2024-10-15 14:50
NVD link : CVE-2024-7292
Mitre link : CVE-2024-7292
CVE.ORG link : CVE-2024-7292
JSON object : View
Products Affected
progress
- telerik_report_server
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts