CVE-2017-11317 is a critical vulnerability affecting Progress Telerik UI for ASP.NET AJAX versions before R1 2017 and R2 before R2 2017 SP2, stemming from weak encryption in the RadAsyncUpload component. This allows unauthenticated remote attackers to perform arbitrary file uploads and execute arbitrary code with high impact on confidentiality, integrity, and availability. The vulnerability has a CVSS score of 9.8 (CRITICAL) and is actively exploited, with public exploit modules available in Metasploit and ExploitDB. It has garnered significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2016.3.1027CPE matchmatch criteria | cpe:2.3:a:telerik:ui_for_asp.net_ajax:*:*:*:*:*:*:*:* | ||
2017.2.503CPE matchmatch criteria | cpe:2.3:a:telerik:ui_for_asp.net_ajax:2017.2.503:*:*:*:*:*:*:* | ||
2017.2.621CPE matchmatch criteria | cpe:2.3:a:telerik:ui_for_asp.net_ajax:2017.2.621:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025