CVE-2023-35815

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 502

Summary

CVE-2023-35815 is a vulnerability affecting DevExpress versions prior to 23.1.3. The issue involves a bypass of the data-source protection mechanism during deserialization of XML data. An attacker can exploit this vulnerability to gain unauthorized access to sensitive data, potentially leading to serious security consequences. The deserialization process is supposed to protect data from unauthorized access; however, in this case, the protection is bypassed, making the data vulnerable. It is recommended that users upgrade to the latest version of DevExpress to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share