Vulnerability record · CVE-2019-19790 · published 13 December 2019
CVE-2019-19790: Progress telerik ui for asp.net ajax path traversal vulnerability
Progress · Telerik Ui For Asp.Net Ajax
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).
Description
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.telerik.com/devtools/aspnet-ajax/controls/chart/overview | Vendor Advisory |
| https://www.telerik.com/forums/-620f6977edef | Vendor Advisory |
| https://www.telerik.com/forums/path-traversal-vulnerability-in-radchart-image-handler | Vendor Advisory |
| https://docs.telerik.com/devtools/aspnet-ajax/controls/chart/overview | Vendor Advisory |
| https://www.telerik.com/forums/-620f6977edef | Vendor Advisory |
| https://www.telerik.com/forums/path-traversal-vulnerability-in-radchart-image-handler | Vendor Advisory |
Track CVE-2019-19790 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19790), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.