An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.telerik.com/devtools/justdecompile/knowledge-base/jd-ja-resources-vulnerability - Vendor Advisory | |
References | () https://www.telerik.com/support/whats-new/justdecompile/release-history/justdecompile-r2-2018-sp1 - Vendor Advisory |
Information
Published : 2018-08-16 20:29
Updated : 2024-11-21 03:50
NVD link : CVE-2018-15122
Mitre link : CVE-2018-15122
CVE.ORG link : CVE-2018-15122
JSON object : View
Products Affected
telerik
- justassembly
- justdecompile
CWE
CWE-20
Improper Input Validation