CVE Vulnerabilities

CVE-2024-8048

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Published: Oct 09, 2024 | Modified: Nov 03, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

Weakness

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Affected Software

NameVendorStart VersionEnd Version
Telerik_reportingProgress*18.2.24.924 (excluding)

Potential Mitigations

References