This is a migrated thread and some comments may be shown as answers.

Security issue in ImageEditor that allows saving the image in an up-level folder

0 Answers 191 Views
ImageEditor
This is a migrated thread and some comments may be shown as answers.
This question is locked. New answers and comments are not allowed.
Telerik Admin
Top achievements
Rank 1
Iron
Telerik Admin asked on 26 Feb 2014, 12:30 PM

The RadImageEditor control allowed saving image files (.png/.jpg/.gif) to an up-level folder on the server when the built-in storing of files is used. This issue did not affect implementations based on the content provider paragidm. It has been fixed since the Q1 2014 release of Telerik UI for ASP.NET AJAX (version 2014.1.225).

If you are using an older version of the controls and you do not wish to upgrade, there are two approaches that you can take in order to resolve the security issue:

Tags
ImageEditor
Asked by
Telerik Admin
Top achievements
Rank 1
Iron
Share this question
or