Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj5r-8wvg-3cxf

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

EPSS

Процентиль: 10%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 7.5
nvd
24 дня назад

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

EPSS

Процентиль: 10%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-321