First published: Mon Oct 08 2018(Updated: )
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik Extensions For Asp.net Mvc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17060 is a vulnerability in Telerik Extensions for ASP.NET MVC (all versions) that allows a remote attacker to access files inside the server's web directory.
The severity of CVE-2018-17060 is medium with a CVSS score of 5.3.
CVE-2018-17060 occurs because Telerik Extensions for ASP.NET MVC (all versions) does not properly whitelist requests, allowing a remote attacker to access files on the server's web directory.
There is no fix for CVE-2018-17060 as the affected product, Telerik Extensions for ASP.NET MVC, has been obsolete since June 2013.
You can find more information about CVE-2018-17060 at the following link: [Telerik Security Alert](https://www.telerik.com/support/code-library/security-alert-for-the-obsolete-telerik-extensions-for-asp-net-mvc)