PT-2019-15960 · Telerik · Telerik Ui For Asp.Net Ajax
Movrment
·
Published
2019-12-13
·
Updated
2025-06-30
·
CVE-2019-19790
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Telerik UI for ASP.NET AJAX versions (all versions of RadChart)
Description
The issue allows a remote attacker to read and delete specific image files on the server through a specially crafted request, exploiting path traversal in RadChart. The affected image extensions include .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, and .WMF.
Recommendations
To resolve the issue, remove RadChart's HTTP handler from the web.config file, specifically the type Telerik.Web.UI.ChartHttpHandler.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telerik Ui For Asp.Net Ajax