Stimulsoft
Stimulsoft Designer: vulnerabilidades y CVE
Stimulsoft Designer tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-25260 | Alta (7.5) | 0.84% | — | 28 mar 2023 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. |
| CVE-2023-25262 | Alta (7.5) | 0.90% | — | 28 mar 2023 | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses… |
| CVE-2023-25263 | Media (5.5) | 0.23% | — | 27 mar 2023 | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The… |
| CVE-2023-25261 | Crítica (9.8) | 1.9% | — | 27 mar 2023 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the… |