Description
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9389 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler). |
References
History
Mon, 30 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress telerik Ui For Asp.net Ajax |
|
| CPEs | cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Telerik ui For Asp.net Ajax
|
Progress
Progress telerik Ui For Asp.net Ajax |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.691Z
Reserved: 2019-12-13T00:00:00.000Z
Link: CVE-2019-19790
No data.
Status : Modified
Published: 2019-12-13T18:15:11.403
Modified: 2025-06-30T13:06:41.513
Link: CVE-2019-19790
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD