CVE-2023-35816
28.04.2025, 16:15
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.Enginsight
Vendor | Product | Version |
---|---|---|
devexpress | devexpress | 𝑥 < 21.2.12 |
devexpress | devexpress | 22.1.8 |
devexpress | devexpress | 22.2.4 |
devexpress | devexpress | 22.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-23 - Relative Path TraversalThe software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
- CWE-704 - Incorrect Type Conversion or CastThe software does not correctly convert an object, resource, or structure from one type to a different type.
References