Skip to main content

Tag: radasyncupload

1 article

Cluttered workstation with computer and technical equipment in a neutral room.

Telerik UI Flaw Exposes Unauthenticated RCE Risk

A newly discovered flaw in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution, thanks to a publicly released proof-of-concept that combines an AES-CBC padding oracle with a type-resolution bug in the RadAsyncUpload control. When certain preconditions are met, this vulnerability can be easily leveraged for devastating effect.

Analyst 207