First published: Tue Mar 31 2020(Updated: )
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik UI for Silverlight | <2020.1.330 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-11414 is high with a severity value of 7.5.
CVE-2020-11414 is an issue discovered in Progress Telerik UI for Silverlight before 2020.1.330.
CVE-2020-11414 impacts Telerik UI for Silverlight by allowing an attacker to upload a file to an unintended location.
To fix CVE-2020-11414, update to version 2020.1.330 or later of Progress Telerik UI for Silverlight.
You can find more information about CVE-2020-11414 at the following link: [link](https://docs.telerik.com/devtools/silverlight/controls/radupload/how-to/secure-upload-file-path).