In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Telerik
Telerik ui For Winforms |
|
CPEs | cpe:2.3:a:telerik:ui_for_winforms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Telerik
Telerik ui For Winforms |
Wed, 12 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | |
Title | Progress UI for WinForms decompression path traversal vulnerability | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2025-02-12T15:31:36.602Z
Reserved: 2025-01-08T17:10:32.725Z
Link: CVE-2025-0332

Updated: 2025-02-12T15:31:25.153Z

Status : Analyzed
Published: 2025-02-12T16:15:42.703
Modified: 2025-02-21T12:03:31.920
Link: CVE-2025-0332

No data.