Web Hack List

Collected research

More Than DoS: Progress Telerik UI for ASP.NET AJAX Unsafe Reflection (CVE-2025-3600)

Investigates request-controlled type resolution and no-argument constructors in Telerik UI. The article separates denial-of-service effects from conditional execution paths, then traces a Sitecore chain that initializes an unsafe assembly resolver through another endpoint and loads an attacker-supplied DLL once file-placement prerequisites are met.

Record

Researcher
Piotr Bazydlo
Published by
watchTowr
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydlo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .