CVE-2024-11628

MEDIUM

Telerik Kendo UI for Vue <6.0.1 - Command Injection

Title source: llm
STIX 2.1

Description

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

Scores

CVSS v3 4.1
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (1)
progress/kendo_ui_for_vue 2.4.0 - 6.1.0
Published Feb 12, 2025
Tracked Since Feb 18, 2026