PT-2019-15960 · Telerik · Telerik Ui For Asp.Net Ajax

Movrment

·

Published

2019-12-13

·

Updated

2025-06-30

·

CVE-2019-19790

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX versions (all versions of RadChart)
Description The issue allows a remote attacker to read and delete specific image files on the server through a specially crafted request, exploiting path traversal in RadChart. The affected image extensions include .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, and .WMF.
Recommendations To resolve the issue, remove RadChart's HTTP handler from the web.config file, specifically the type Telerik.Web.UI.ChartHttpHandler.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2019-19790

Affected Products

Telerik Ui For Asp.Net Ajax