← Vulnerability feed

Vulnerability record · CVE-2019-19790 · published 13 December 2019

CVE-2019-19790: Progress telerik ui for asp.net ajax path traversal vulnerability

Progress · Telerik Ui For Asp.Net Ajax

Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).

9.8 CVSS 3.1 Critical EPSS 3.0% · top 13.2% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19790 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11357Telerik UI for ASP.NET AJAX RadAsyncUpload unrestricted file uploadProgress Telerik UI for ASP.NET AJAX before R2 2017 SP2 fails to properly restrict user input to the RadAsyncUpload control, allowing arbitrary file …KEVEPSS 78%analysed9.8CVE-2026-6023Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…EPSS 0.73%9.8CVE-2021-28141Progress telerik ui for asp.net ajax missing authorization vulnerabilityAn issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…EPSS 2.2%8.1CVE-2026-13185Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize…EPSS 0.67%8.1CVE-2026-13186Progress telerik ui for asp.net ajax path traversal vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploite…EPSS 0.73%8.1CVE-2026-13187Progress telerik ui for asp.net ajax vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processin…EPSS 0.47%8.1CVE-2026-13190Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation…EPSS 0.67%8.1CVE-2026-13181Progress telerik ui for asp.net ajax vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attack…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2019-19790), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.