CVE Feed

    Dashboard / CVE / CVE-2023-25261

    CVE-2023-25261

    Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which reads or writes local directories and files. It is also possible for the attacker to prepare a report which has a variable that holds the gathered data and render it in the report.

    Published:Mar 27, 2023
    Last Modified:Feb 19, 2025
    EPS:Mar 27, 2023
    EPSS Score:0.05153
    CVSS Score:9.8

    Affected Products

    Vendor
    Stimulsoft
    Product
    Designer
    Vendor
    Stimulsoft
    Product
    Viewer

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High