QID 375317

QID 375317: Telerik Extensions for ASP.NET MVC Unrestricted File Reading Vulnerability

Telerik Extension for ASP.NET MVC is a professional grade UI library with 100+ components for building modern and feature-rich applications.

Telerik Extensions for ASP.NET MVC does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory.

Affected Versions: All versions of Telerik Extensions for ASP.NET MVC

QID Detection Logic:(Authenticated)
It checks for the file version of Telerik.CommonInstaller.Application.dll.

On successful exploitation, it allows an attacker unrestricted file reading that can allow access to files inside server's web directory.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    There will be no updates from vendor as it is obsolete.

    CVEs related to QID 375317

    Software Advisories
    Advisory ID Software Component Link