Improper security restrictions in UI for ASP.NET AJAX - CVE-2017-11357
Published: December 19, 2017 / Updated: January 26, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in Progress Telerik User Interface (UI) for ASP.NET AJAX due to use of user-supplied input by RadAsyncUpload without modification or validation. A remote attacker can upload arbitrary files and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
HP Performance Center
How to mitigate CVE-2017-11357
Links to Public Exploits and PoC-codes
- Exploit #6282 - Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload (June 17, 2021)
- Exploit #2071 - RAU_crypto (Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)) (March 18, 2020)
- Exploit #2165 - dp_crypto (Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)) (March 18, 2020)