Telerik Reporting < 11.0.17.406 Cross-Site Scripting

medium Web App Scanning Plugin ID 112490

Synopsis

Telerik Reporting < 11.0.17.406 Cross-Site Scripting

Description

The remote web server is running a version of Telerik Reporting that is affected by a Cross-Site Scripting (XSS) vulnerability due to a flaw in Telerik.ReportViewer.WebForms.dll which allows a remote attacker to use specially crafted requests that can lead to arbitrary HTML and script code injection into a user's browser to be executed within the security context of the affected site.

Solution

Upgrade to Telerik Reporting R1 2017 SP2 (version 11.0.17.406) or later.

See Also

https://www.telerik.com/support/whats-new/reporting/release-history/telerik-reporting-r1-2017-sp2-(version-11-0-17-406)

https://www.veracode.com/blog/research/anatomy-cross-site-scripting-flaw-telerik-reporting-module

Plugin Details

Severity: Medium

ID: 112490

Type: remote

Published: 11/20/2018

Updated: 9/7/2021

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2017-9140

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2017-9140

Vulnerability Information

CPE: cpe:2.3:a:progress:telerik_reporting:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Patch Publication Date: 4/6/2017

Vulnerability Publication Date: 4/6/2017

Reference Information

CVE: CVE-2017-9140