First published: Wed Aug 23 2017(Updated: )
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik UI for ASP.NET AJAX | <2020.1.114 | |
Progress Telerik UI for ASP.NET AJAX | <=2017.2.621 | |
Telerik UI for ASP.NET AJAX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11357 is considered a critical vulnerability due to its potential for arbitrary file uploads and code execution.
To fix CVE-2017-11357, users should upgrade to Telerik UI for ASP.NET AJAX versions later than R2 2017 SP2.
CVE-2017-11357 can enable remote attackers to perform arbitrary file uploads and execute arbitrary code on the server.
CVE-2017-11357 affects Telerik UI for ASP.NET AJAX versions prior to R2 2017 SP2, including all versions up to 2017.2.621.
No, CVE-2017-11357 can be exploited by an unauthenticated attacker, making it particularly dangerous.