CVE-2017-11357: Telerik User Interface (UI) for ASP.NET AJAX
EPSS77.6%No. 648 of 1739 in KEV
CVE year2017~6 yrs before listing
Same vendor in KEV2
Same product2
| Field | Value |
|---|---|
| Vendor | Telerik |
| Product | User Interface (UI) for ASP.NET AJAX |
| Name | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability |
| Added to KEV | 2023-01-26 |
| US federal due date | 2023-02-16 |
| Ransomware use | Known |
| CWE | CWE-20 |
CISA description
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2017-11317 | Telerik User Interface (UI) for ASP.NET AJAX | 2022-04-11 | 84.1% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Telerik User Interface (UI) for ASP.NET AJAX vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-26.