The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE: the vendor disputes this because the retrieved source code is only the DevExpress client-side application code that is, of course, intentionally readable by web browsers (a site's custom code and data is never accessible via an IDOR approach).
History

Thu, 15 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-18T00:00:00.000Z

Updated: 2025-05-15T15:34:46.563Z

Reserved: 2022-09-26T00:00:00.000Z

Link: CVE-2022-41479

cve-icon Vulnrichment

Updated: 2024-08-03T12:42:46.449Z

cve-icon NVD

Status : Modified

Published: 2022-10-18T14:15:09.807

Modified: 2025-05-15T16:15:26.417

Link: CVE-2022-41479

cve-icon Redhat

No data.