Umbra Wiki cve cve/CVE-2017-11357
Back to wiki

CVE-2017-11357 — Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

provenance: imported · CVE: CVE-2017-11357

CVE-2017-11357: Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Telerik
Product User Interface (UI) for ASP.NET AJAX
Date added 2023-01-26
Due date 2023-02-16
Ransomware campaign use Known

Description

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-11357
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog