CVE-2017-11357 - Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Project:Telerik
Product:User Interface (UI) for ASP.NET AJAX
Date Added:2023-01-26Due Date:2023-02-16
Vulnerability Name
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Description
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference
https://nvd.nist.gov/vuln/detail/CVE-2017-11357