logo

CVE-2017-11357 - Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

CVE-2017-11357

Telerik | User Interface (UI) for ASP.NET AJAX

  • Date Added:
  • 2023-01-26
  • Due Date:
  • 2023-02-16
Vulnerability Name

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Description

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply updates per vendor instructions.

Additional Notes
https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357

Free online web security scanner