Back

CRITICAL KEV Used in ransomware campaigns

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code

Published Aug 23, 2017 ·Due Feb 16, 2023

Description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 23, 2017
Updated Aug 14, 2026
Reserved Jul 16, 2017
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Aug 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Aug 23, 2017
Updated Aug 14, 2026
Exploited since Jan 26, 2023
EUVD-2017-2986