mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
19 lines
826 B
Markdown
19 lines
826 B
Markdown
![]() |
### [CVE-2023-25263](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25263)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://cves.at/posts/cve-2023-25263/writeup/
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
||
|
- https://github.com/trustcves/CVE-2023-25263
|
||
|
|