MEDIUM · 5.3

CVE-2018-17060

Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolet...

Vulnerability Description

Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ProgressTelerik Extensions For Asp.Net MvcAll versions

References

FAQ

What is CVE-2018-17060?

CVE-2018-17060 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolet...

How severe is CVE-2018-17060?

CVE-2018-17060 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-17060?

Check the references section above for vendor advisories and patch information. Affected products include: Progress Telerik Extensions For Asp.Net Mvc.