logo
Home/CVEs/CVE-2017-11357/

CVE-2017-11357 - Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Project:Telerik

Product:User Interface (UI) for ASP.NET AJAX

Date Added:2023-01-26Due Date:2023-02-16

Vulnerability Name

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Description

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply updates per vendor instructions.

Additional Notes

https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference

https://nvd.nist.gov/vuln/detail/CVE-2017-11357