CVE-2024-11628

In ProgressĀ® TelerikĀ® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:kendo_ui_for_vue:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-12 17:15

Updated : 2025-06-27 19:18


NVD link : CVE-2024-11628

Mitre link : CVE-2024-11628

CVE.ORG link : CVE-2024-11628


JSON object : View

Products Affected

progress

  • kendo_ui_for_vue
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')