7.5
CVSSv3

CVE-2022-41479

Published: 18/10/2022 Updated: 20/10/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows malicious users to access the application source code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

devexpress asp.net web forms controls 19.2.3