CVE-2018-17060: Progress Telerik Extensions For ASP.NET Mvc
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
Affected products
- Progress Telerik Extensions For ASP.NET Mvc: any version
Published 2018-10-08. Last modified 2026-06-17.