peter bassill · operator
$ cve CVE-2017-11357 JSON

CVE-2017-11357 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 77.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-02-16.

Description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS77.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2023-02-16
Public exploityes
Published2017-08-23
Last modified2026-08-14

CISA KEV

NameTelerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Added2023-01-26
Due2023-02-16
Vendor / productTelerik / User Interface (UI) for ASP.NET AJAX
Ransomware useknown

Affected (1)

VendorProduct
progresstelerik ui for asp.net ajax

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD