Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2017-11357

Telerik | User Interface (UI) for ASP.NET AJAXAdded 2023-01-26Remediation Deadline 2023-02-16Active Ransomware Campaign

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-20

References