HIGH🇵🇱 Wersja polska

CVE-2023-25262

CVSS 7.5v3.1pub. 2023-03-28upd. 2026-07-09

Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Stimulsoft Designer

    APP
    Stimulsoft
    2023.1.32023.1.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2023-25261CRITICAL9.8PL ✓same product

RCE w Stimulsoft Designer i Viewer — brak ograniczeń dostępu do systemu plików

CVE-2023-25260HIGH7.5same product

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-25263MEDIUM5.5same product

In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll...

CVE-2024-24398CRITICAL9.8PL ✓same vendor

Path Traversal umożliwiający RCE w Stimulsoft Dashboard.JS

CVE-2021-42777CRITICAL9.8PL ✓same vendor

RCE w Stimulsoft Reports — wykonanie kodu C# przez raport