Collected research
More Than DoS: Progress Telerik UI for ASP.NET AJAX Unsafe Reflection (CVE-2025-3600)
Investigates request-controlled type resolution and no-argument constructors in Telerik UI. The article separates denial-of-service effects from conditional execution paths, then traces a Sitecore chain that initializes an unsafe assembly resolver through another endpoint and loads an attacker-supplied DLL once file-placement prerequisites are met.
Record
- Researcher
- Piotr Bazydlo
- Published by
- watchTowr
- Date
- Topic
- Server
In the archive
Related sources
- SSO Wars: The Token Menace Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydlo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .