CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
⚠ KEVEPSS 99.7%
Description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
How to fix CVE-2019-18935
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2019-18935 being exploited?
Yes — CVE-2019-18935 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.