CVE-2019-18935

⚠ KEVEPSS 93.6%

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Added to CISA KEV: 11/3/2021

Description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Affected packages (0)

No package mapping in OSV.