Exploited Vulnerabilities Daily
🌐 English

Home › Progress

CVE-2017-9248: Progress ASP.NET AJAX and Sitefinity

EPSS75.0%No. 674 of 1739 in KEV
CVE year2017~4 yrs before listing
Same vendor in KEV9
Same product1
FieldValue
VendorProgress
ProductASP.NET AJAX and Sitefinity
NameProgress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Added to KEV2021-11-03
US federal due date2022-05-03
Ransomware useUnknown
CWECWE-522

CISA description

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

NVD — CVE-2017-9248

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Progress ASP.NET AJAX and Sitefinity vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.