Loading
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Use CWE-434, Telerik vendor hub and Ui For Asp.Net Ajax product page to widen CVE-2017-11357 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-18935, CVE-2017-11317 and CVE-2017-9248 for nearby disclosures in the same product family.