PoC Index

CVE-2024-4358

KEVCRITICAL 9.8EPSS 97.5%

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
97.48% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-06-13
Nuclei
critical
Published
2024-05-29
Updated
2025-10-21

Proof-of-concept exploits (7)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related