CVE-2023-35816
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Affected (4)
Products: Devexpress: Devexpress
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.2.12 |
Related CWEs
CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-704
Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.
References (4)
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Timeline
No history available yet.