VULNERABILITY INTELLIGENCE
CVE-2014-2575
CVSS score6.5 MEDIUM
EPSS probability8.92%
CISA KEVNot currently listed
Published2014-06-06
Last modified2026-06-17
Description
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.