CVE-2018-17060: Improper Access Control in Telerik Extensions
(updated )
Telerik Extensions for ASP.NET MVC (all versions) does not allow list requests, which can allow a remote attacker to access files inside the server’s web directory. NOTE: this product has been obsolete since June 2013.
References
Detect and mitigate CVE-2018-17060 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →