PT-2019-15960 · Telerik · Telerik Ui For Asp.Net Ajax

Movrment

·

Publicado

2019-12-13

·

Atualizado

2025-06-30

·

CVE-2019-19790

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX versions (all versions of RadChart)
Description The issue allows a remote attacker to read and delete specific image files on the server through a specially crafted request, exploiting path traversal in RadChart. The affected image extensions include .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, and .WMF.
Recommendations To resolve the issue, remove RadChart's HTTP handler from the web.config file, specifically the type Telerik.Web.UI.ChartHttpHandler.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19790

Produtos afetados

Telerik Ui For Asp.Net Ajax