Executive brief
Telerik UI for ASP.NET AJAX contains an insecure direct object reference (IDOR) vulnerability in the RadAsyncUpload component. The flaw allows remote attackers to bypass input restrictions to perform arbitrary file uploads, potentially leading to remote code execution.
Affected products
- Telerik UI for ASP.NET AJAX before R2 2017 SP2 (2017.2.711)
Timeline
- 2017-08-23: disclosed: NVD Published Date
- 2018-01-24: other: Exploit-DB entry published
- 2023-01-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-01-26: advisory: CISA advisory published