CVE-2021-28141
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_ and inject a command at the end of the URI. NOTE: the vendor states that this is not a vulnerability. The request's output does not indicate that a "true" command was executed on the server, and the request's output does not leak any private source code or data from the server
Se detectó un problema en Progress Telerik UI para ASP.NET AJAX versión 2021.1.224. Permite el acceso no autorizado a MicrosoftAjax.js por medio del archivo Telerik.Web.UI.WebResource.axd. Esto puede permitir a un atacante conseguir acceso no autorizado al servidor y ejecutar código. Para explotar, uno debe usar el parámetro _TSM_HiddenField_ e inyectar un comando al final del URI
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-11 CVE Reserved
- 2021-03-11 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-11-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://gist.github.com/shreyasfegade/e2480e26b2ed1d0c7175ecf7cb15f9c1 | 2024-08-03 | |
https://pastebin.com/JULpfvFJ | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | 2021.1.224 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version "2021.1.224" | - |
Affected
|