CVE-2018-15122

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/08/2018
Last modified:
15/10/2018

Description

An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:telerik:justassembly:*:*:*:*:*:*:*:* 2018.1.323.2 (including)
cpe:2.3:a:telerik:justdecompile:*:*:*:*:*:*:*:* 2018.2.605.0 (including)