Progress Telerik KendoReact
cpe:2.3:a:telerik:kendoreact:*:*:*:*:*:*:*
- >= 3.5.0, <= 9.1.0
A vulnerability exists in Progress Telerik KendoReact versions 3.5.0 prior to 9.4.0, allowing attackers to introduce or modify properties within the global prototype chain. This manipulation can lead to denial-of-service conditions or command injection vulnerabilities.
Exploitation of this vulnerability can cause denial-of-service conditions or allow for command injection.
Users are advised to update to Progress Telerik KendoReact version 9.4.0 or later. The updated packages are available via npm. For version 9.4.0 update instructions, refer to the KendoReact installation documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.