HIGH🇬🇧 English

CVE-2023-25262

CVSS 7.5v3.1pub. 2023-03-28upd. 2026-07-09

Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Stimulsoft Designer

    APP
    Stimulsoft
    2023.1.32023.1.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SSRF
CWE
Referencje

Powiązane podatności

CVE-2023-25261CRITICAL9.8PL ✓ten sam produkt

RCE w Stimulsoft Designer i Viewer — brak ograniczeń dostępu do systemu plików

CVE-2023-25260HIGH7.5ten sam produkt

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-25263MEDIUM5.5ten sam produkt

In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll...

CVE-2024-24398CRITICAL9.8PL ✓ten sam vendor

Path Traversal umożliwiający RCE w Stimulsoft Dashboard.JS

CVE-2021-42777CRITICAL9.8PL ✓ten sam vendor

RCE w Stimulsoft Reports — wykonanie kodu C# przez raport