Vulnerability Description
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Telerik Extensions For Asp.Net Mvc | All versions |
References
- https://www.telerik.com/support/code-library/security-alert-for-the-obsolete-telVendor Advisory
- https://www.telerik.com/support/code-library/security-alert-for-the-obsolete-telVendor Advisory
FAQ
What is CVE-2018-17060?
CVE-2018-17060 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolet...
How severe is CVE-2018-17060?
CVE-2018-17060 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17060?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Telerik Extensions For Asp.Net Mvc.