CVE-2023-35815
CVSS 3.1 Score 3.5 of 10 (low)
Details
Summary
CVE-2023-35815 is a vulnerability affecting DevExpress versions prior to 23.1.3. The issue involves a bypass of the data-source protection mechanism during deserialization of XML data. An attacker can exploit this vulnerability to gain unauthorized access to sensitive data, potentially leading to serious security consequences. The deserialization process is supposed to protect data from unauthorized access; however, in this case, the protection is bypassed, making the data vulnerable. It is recommended that users upgrade to the latest version of DevExpress to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DevExpress
Affected Vendors
- DevExpress