PT-2026-102454 · Progress Telerik · Fiddler Everywhere
CVSS v3.1
5.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Progress Telerik Fiddler Everywhere versions prior to 8.2.0
Description
Exposure of privileged Inter-Process Communication (IPC) functionality allows a local, low-privileged attacker to replace the application UI or settings with attacker-controlled content. This is possible if the attacker can modify application launch parameters and persuade a user to start the application. Successful exploitation may lead to the disclosure of OAuth authentication tokens, the execution of locally accessible programs, or the unauthorized modification of application-generated configuration files.
Recommendations
Update Progress Telerik Fiddler Everywhere to version 8.2.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fiddler Everywhere