File Upload Vulnerability in Progress Telerik UI for Silverlight
CVE-2020-11414
7.5HIGH
What is CVE-2020-11414?
A security issue was identified in the Telerik UI for Silverlight, specifically within the RadUploadHandler class. Prior to version 2020.1.330, the upload handler did not properly validate the file location for uploads. This oversight allowed for crafted web requests to potentially upload files to arbitrary locations on the server, posing a risk of unauthorized file access and server exploitation. It is recommended to upgrade to the latest version to mitigate these security concerns.