References https://www.tenablecloud.cn/plugins/nessus/200090 https://www.anquanke.com/post/id/297127 https://avd.aliyun.com/detail?id=AVD-2024-1800 https://www.venustech.com.cn/new_type/aqtg/20240605/27616.html https://rivers.chaitin.cn/blog/cqi83vp0lnedo7thpq50 https://www.anquanke.com/post/id/298445 https://www.tenablecloud.cn/plugins/was/114294 https://cn-sec.com/archives/2820032.html https://cn-sec.com/archives/2817491.html https://cn-sec.com/archives/2836412.html https://buaq.net/go-252665.html https://www.telerik.com/report-server/documentation/knowledge-base/deserialization-vulnerability-cve-2024-1800 https://github.com/sinsinology/CVE-2024-4358 https://www.sentinelone.com/vulnerability-database/cve-2024-1800/ https://www.broadcom.com/support/security-center/protection-bulletin/cve-2024-4358-cve-2024-1800-vulnerabilities-in-telerik-report-server https://www.cve.org/CVERecord?id=CVE-2024-1800 https://arcticwolf.com/resources/blog/cve-2024-4358-cve-2024-1800/ https://csirt.divd.nl/cases/DIVD-2024-00023/ https://www.tenable.com/plugins/was/114294 https://www2.gov.bc.ca/assets/gov/british-columbians-our-governments/services-policies-for-government/information-management-technology/information-security/vulnerability-risk-management/vulnerability-reports/n24-255_progress_telerik_security_advisory.pdf https://censys.com/advisory/march-26-2024-progress-telerik-report-server-rce-cve-2024-1800/ https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=34707 https://www.zerodayinitiative.com/advisories/ZDI-24-403/ https://www.savetime.com.tw/Symantec-Protection-Bulletin-Weekly.asp https://metc.njtc.edu.cn/info/1141/4822.htm https://nic.seu.edu.cn/info/1047/1240.htm https://feedly.com/cve/CVE-2024-1800 https://www.telerik.com/support/whats-new/report-server/release-history/progress-telerik-report-server-2024-q1-(10-0-24-305) https://www.telerik.com/forums/request-for-telerikreportserver-10-0-24-130-exe-download https://www.securityweek.com/progress-patches-critical-vulnerability-in-telerik-report-server/ https://hivepro.com/threat-advisory/chained-flaws-in-progress-telerik-report-server-enable-unauthenticated-rce/ https://www.theregister.com/security/2024/07/26/critical-bug-in-progress-telerik-report-server-leads-to-rce/511188 https://thehackernews.com/2024/06/telerik-report-server-flaw-could-let.html
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传JeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request Forgery用友时空-KSOA /worksheet/agent_work_report.jsp SQL 注入漏洞森鑫炬水务企业综合运营平台 Reports/File/Get 接口任意文件读取PoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java DeserializationPoCCVE-2026-23536: Feast Feature Server <=0.58.0 - Arbitrary File ReadPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL Injection網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-35037: Ech0 < 4.2.8 - Server-Side Request Forgery