CVE-2020-11414: Path Traversal
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11414?
The severity of CVE-2020-11414 is high with a severity value of 7.5.
What is CVE-2020-11414?
CVE-2020-11414 is an issue discovered in Progress Telerik UI for Silverlight before 2020.1.330.
How does CVE-2020-11414 impact Telerik UI for Silverlight?
CVE-2020-11414 impacts Telerik UI for Silverlight by allowing an attacker to upload a file to an unintended location.
How do I fix CVE-2020-11414?
To fix CVE-2020-11414, update to version 2020.1.330 or later of Progress Telerik UI for Silverlight.
Where can I find more information about CVE-2020-11414?
You can find more information about CVE-2020-11414 at the following link: [link](https://docs.telerik.com/devtools/silverlight/controls/radupload/how-to/secure-upload-file-path).