Tag: radasyncupload
1 article

Telerik UI Flaw Exposes Unauthenticated RCE Risk
A newly discovered flaw in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution, thanks to a publicly released proof-of-concept that combines an AES-CBC padding oracle with a type-resolution bug in the RadAsyncUpload control. When certain preconditions are met, this vulnerability can be easily leveraged for devastating effect.