Loading HuntDB...

GHSA-c655-3j45-33xw

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (In 2019.3.1023 but not earlier versions, a non-default setting can prevent exploitation.)

Related CVEs

Key Information

GHSA ID
GHSA-c655-3j45-33xw
Published
May 24, 2022 5:03 PM
Last Modified
July 25, 2024 3:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: October 2, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.