CVE-2019-18935
⚠ KEVEPSS 93.6%Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Added to CISA KEV: 11/3/2021
Description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Affected packages (0)
No package mapping in OSV.