The DevExpress Resource Handler (ASPxHttpHandlerModule)...
High severity
Unreviewed
Published
Oct 18, 2022
to the GitHub Advisory Database
•
Updated Aug 2, 2024
Description
Published by the National Vulnerability Database
Oct 18, 2022
Published to the GitHub Advisory Database
Oct 18, 2022
Last updated
Aug 2, 2024
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code.
References