First published: Tue Oct 18 2022(Updated: )
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DevExpress ASP.NET Web Forms Controls | =19.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-41479.
The severity of CVE-2022-41479 is high with a CVSS score of 7.5.
The affected software is DevExpress ASP.NET Web Forms Controls version 19.2.3.
The CWE ID for this vulnerability is CWE-639.
To fix CVE-2022-41479, upgrade to a version of DevExpress ASP.NET Web Forms Controls that is not affected by this vulnerability.