An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-3768 An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:28:13.986Z

Reserved: 2020-03-31T00:00:00

Link: CVE-2020-11414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-31T13:15:13.177

Modified: 2024-11-21T04:57:53.920

Link: CVE-2020-11414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses