CVE-2023-25263

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
27/03/2023
Last modified:
03/04/2023

Description

In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stimulsoft:designer:2023.1.4:*:*:*:desktop:*:*:*
cpe:2.3:a:stimulsoft:designer:2023.1.4:*:*:*:web:*:*:*
cpe:2.3:a:stimulsoft:designer:2023.1.5:*:*:*:desktop:*:*:*
cpe:2.3:a:stimulsoft:designer:2023.1.5:*:*:*:web:*:*:*