{"cvss":9.8,"datePublished":"2023-01-26","dateUpdated":"2023-01-26","description":"Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.","dueDate":"2023-02-16","id":"CVE-2017-11357","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357","product":"User Interface (UI) for ASP.NET AJAX","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability","vendor":"Telerik"}