In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://docs.telerik.com/report-server/knowledge-base/weak-password-requirement-cve-2024-7293 | vendor advisory |