Description
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29225 | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems. |
References
History
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-19T15:47:59.474Z
Reserved: 2023-02-06T00:00:00.000Z
Link: CVE-2023-25263
Updated: 2024-08-02T11:18:36.308Z
Status : Modified
Published: 2023-03-27T21:15:11.093
Modified: 2024-11-21T07:49:22.017
Link: CVE-2023-25263
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD