CVE-2019-18935
Essential information
- Published
- 03/11/2021 01:00
- Modified
- 20/12/2025 21:23
- Author
- Cybersecurity and Infrastructure Security Agency
- Creator
- Cybersecurity and Infrastructure Security Agency
- CISA KEV
- Yes
- CWE
- —
- CVSS vector
- — — —
Description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
NVD status
- NVD
- View on NVD