DevExpress
cpe:2.3:a:devexpress:devexpress:*:*:*:*:*:*:*
- < 23.1.3
- < 22.2.6
- < 22.2.3
- < 22.1.9
- < 22.1.7
- < 21.2.12
A vulnerability exists in DevExpress products prior to version 23.1.3, allowing for insecure and arbitrary conversions using TypeConverters. This issue arises from improper handling of data types during XML deserialization, which can be exploited to bypass data source protection and potentially lead to unauthorized operations.
Exploitation of this vulnerability could result in unauthorized operations being performed, due to the insecure handling of data types that could be manipulated through the vulnerability.
The vulnerability can be reproduced by using a version of DevExpress prior to 23.1.3. During the exploitation, an XML file can be crafted to include specific data types that, when deserialized by the application, will be converted using an arbitrary TypeConverter. This can be done by uploading the crafted XML file through a feature that accepts XML input and processes it without proper validation.
Users are advised to update to DevExpress version 23.1.3 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.