First published: Mon Apr 28 2025(Updated: )
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35816 is considered a critical vulnerability due to its ability to allow arbitrary TypeConverter conversion.
To fix CVE-2023-35816, update your DevExpress product to version 23.1.3 or later.
CVE-2023-35816 affects all versions of DevExpress prior to 23.1.3.
CVE-2023-35816 can facilitate attacks that exploit unsafe TypeConverter conversions, potentially allowing for execution of arbitrary code.
CVE-2023-35816 was disclosed on April 27, 2023.