Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcrv-gh25-252c

Опубликовано: 22 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

EPSS

Процентиль: 43%
0.0054
Низкий

8.1 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
nvd
4 месяца назад

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

EPSS

Процентиль: 43%
0.0054
Низкий

8.1 High

CVSS3

Дефекты

CWE-502