GHSA-v4pr-w7x8-m4mgMediumCVSS 5.5

In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the...

Published
March 27, 2023
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.

🔗 References (5)