← Browse

CVE-2017-11357

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
77.7%
99.5th percentile
CISA KEV
Listed
Added 2023-01-26 · patch by 2023-02-16
Weakness / dates
CWE-434
Published 2017-08-23 · modified 2026-08-14

Description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Affected

progress

References

Official: NVD · CVE.org