CVE-2017-11357

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

  • Published Aug 23, 2017
  • CVSS 9.8 critical
  • 77.7% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

CVE-2017-11357 at the National Vulnerability Database