A TantoSec proofofconcept turns an AESCBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution but only against applications in a specific nondefault configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity