Vulnerabilities > Telerik > UI FOR ASP NET Ajax > 2017.3.913

DATE CVE VULNERABILITY TITLE RISK
2019-12-11 CVE-2019-18935 Deserialization of Untrusted Data vulnerability in Telerik UI for Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
network
low complexity
telerik CWE-502
critical
9.8
2017-08-23 CVE-2017-11357 Unrestricted Upload of File with Dangerous Type vulnerability in Telerik UI for Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
network
low complexity
telerik CWE-434
critical
9.8