Progress Telerik UI for WinUI
cpe:2.3:a:telerik:ui_for_winui:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.11.0
A command injection vulnerability exists in Progress Telerik UI for WinUI, affecting versions through 2024 Q4 (2.11.0). The issue arises from improper handling of hyperlink elements, which could allow an attacker to inject and execute arbitrary commands.
Exploitation of this vulnerability could lead to unauthorized command execution within the context of the application.
Users can upgrade to Progress Telerik UI for WinUI 2025 Q1 (3.0.0) to address this vulnerability. Instructions for updating are available in the Telerik documentation. Customers with a Telerik UI for WinUI license can access the updated version through the Telerik Product Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.