PT-2022-25884 · Devexpress · Devexpress Asp.Net
Published
2022-10-18
·
Updated
2024-08-03
·
CVE-2022-41479
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DevExpress ASP.NET Web Forms Build version 19.2.3
Description
The DevExpress Resource Handler (ASPxHttpHandlerModule) does not verify the referenced objects in the "/DXR.axd?r=" HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) issue, allowing attackers to access the application source code. Note that the vendor disputes this, stating the retrieved source code is only the DevExpress client-side application code, which is intentionally readable by web browsers, and a site's custom code and data is never accessible via this approach.
Recommendations
For version 19.2.3, consider restricting access to the "/DXR.axd" API endpoint to minimize the risk of exploitation, as a temporary workaround, until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devexpress Asp.Net