CVE-2017-11357
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
CISA KEV
- Vendor
- Telerik
- Product
- User Interface (UI) for ASP.NET AJAX
- Due date
- 2023-02-16
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.