Описание
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
Уязвимые конфигурации
Конфигурация 1Версия от 2024.4.1114 (включая) до 2026.1.421 (исключая)
cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.0054
Низкий
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 8.1
github
4 месяца назад
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
EPSS
Процентиль: 43%
0.0054
Низкий
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502