Arbitrary Code Execution via Insecure Deserialization in DevExpress.XtraReports.UI

Arbitrary Code Execution via Insecure Deserialization in DevExpress.XtraReports.UI

CVE-2021-36483 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

Learn more about our Web Application Penetration Testing UK.