CVE-2023-35814

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devexpress:devexpress:*:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:22.1.8:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:22.2.4:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:22.2.5:*:*:*:*:*:*:*

History

05 Jun 2025, 14:29

Type Values Removed Values Added
CPE cpe:2.3:a:devexpress:devexpress:22.2.5:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:*:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:22.1.8:*:*:*:*:*:*:*
cpe:2.3:a:devexpress:devexpress:22.2.4:*:*:*:*:*:*:*
First Time Devexpress devexpress
Devexpress
References () https://code-white.com/public-vulnerability-list/ - () https://code-white.com/public-vulnerability-list/ - Vendor Advisory
References () https://supportcenter.devexpress.com/ticket/details/t1141158/missing-protection-of-xtrareport-serialized-data-in-asp-net-web-forms - () https://supportcenter.devexpress.com/ticket/details/t1141158/missing-protection-of-xtrareport-serialized-data-in-asp-net-web-forms - Permissions Required
References () https://supportcenter.devexpress.com/ticket/details/t1158413/the-allowpassingdatasourceconnectionparameterstoclient-method-may-allow-untrusted-access - () https://supportcenter.devexpress.com/ticket/details/t1158413/the-allowpassingdatasourceconnectionparameterstoclient-method-may-allow-untrusted-access - Permissions Required
References () https://supportcenter.devexpress.com/ticket/details/t1160535/web-reporting-well-formed-request-to-a-report-control-s-backend-can-use - () https://supportcenter.devexpress.com/ticket/details/t1160535/web-reporting-well-formed-request-to-a-report-control-s-backend-can-use - Permissions Required
References () https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023 - () https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023 - Permissions Required

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) DevExpress anterior a 23.1.3 no protege adecuadamente los datos serializados de XtraReport en formularios web ASP.NET.

28 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-28 16:15

Updated : 2025-06-05 14:29


NVD link : CVE-2023-35814

Mitre link : CVE-2023-35814

CVE.ORG link : CVE-2023-35814


JSON object : View

Products Affected

devexpress

  • devexpress
CWE
CWE-502

Deserialization of Untrusted Data