Progress Telerik UI for ASP.NET AJAX through 2019.3.1023...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 25, 2024
Description
Published by the National Vulnerability Database
Dec 11, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jul 25, 2024
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (In 2019.3.1023 but not earlier versions, a non-default setting can prevent exploitation.)
References