June 14, 2024, 7:09 p.m. | Alan David Foster

Rapid7 Blog blog.rapid7.com

New module content (5)


Telerik Report Server Auth Bypass


Authors: SinSinology and Spencer McIntyre

Type: Auxiliary

Pull request: #19242 contributed by zeroSteiner

Path: scanner/http/telerik_report_server_auth_bypass

AttackerKB reference: CVE-2024-4358


Description: This adds an exploit for CVE-2024-4358 which is an authentication bypass in Telerik Report Server versions

auth authentication authentication bypass authors bypass contributed cve cve-2024 cve-2024-4358 exploit http metasploit metasploit weekly wrapup path reference report request scanner server spencer telerik weekly wrap-up

Information Technology Specialist I: Windows Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, California

Information Technology Specialist I, LACERA: Information Security Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, CA

Vice President, Controls Design & Development-7

@ State Street | Quincy, Massachusetts

Vice President, Controls Design & Development-5

@ State Street | Quincy, Massachusetts

Data Scientist & AI Prompt Engineer

@ Varonis | Israel

Contractor

@ Birlasoft | INDIA - MUMBAI - BIRLASOFT OFFICE, IN