PT-2019-15960 · Telerik · Telerik Ui For Asp.Net Ajax

·

CVE-2019-19790

·

Published

2019-12-13

·

Updated

2025-06-30

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX versions (all versions of RadChart)
Description The issue allows a remote attacker to read and delete specific image files on the server through a specially crafted request, exploiting path traversal in RadChart. The affected image extensions include .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, and .WMF.
Recommendations To resolve the issue, remove RadChart's HTTP handler from the web.config file, specifically the type Telerik.Web.UI.ChartHttpHandler.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19790

Affected Products

Telerik Ui For Asp.Net Ajax