CVE-2023-35815: Critical severity openmairie openpresse vulnerability
Published Apr 28, 2025
·Updated
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
Affected Software
5 affected components
DevExpress DevExpress<23.1.3
DevExpress DevExpress<21.2.12
DevExpress DevExpress=22.1.8
DevExpress DevExpress=22.2.4
DevExpress DevExpress=22.2.5
Event History
Apr 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35815?
CVE-2023-35815 is considered a high-severity vulnerability due to its potential impact on data-source protection mechanisms.
2
How do I fix CVE-2023-35815?
To fix CVE-2023-35815, upgrade to DevExpress version 23.1.3 or later as it contains the necessary security patches.
3
What type of vulnerability is CVE-2023-35815?
CVE-2023-35815 is an XML deserialization vulnerability that allows for a data-source protection mechanism bypass.
4
What versions of DevExpress are affected by CVE-2023-35815?
CVE-2023-35815 affects all versions of DevExpress prior to version 23.1.3.
5
Is CVE-2023-35815 remotely exploitable?
Yes, CVE-2023-35815 can be remotely exploited if the application processes untrusted XML data.