CVE-2024-8014 is a high-severity object injection vulnerability affecting Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), enabling remote code execution through insecure type resolution. With a CVSS score of 8.8, this vulnerability presents a significant risk due to its low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, organizations using affected versions should prioritize patching to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.2.24.924CPE matchmatch criteria | cpe:2.3:a:progress:telerik_reporting:*:*:*:*:*:*:*:* | ||
>= 18.2.24.806, < 18.2.24.924CPE match | cpe:2.3:a:progress:telerik_reporting:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.