目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-25262— Stimulsoft GmbH Stimulsoft Designer 代码问题漏洞

AI 预测 9.1 利用难度: 较易 EPSS 0.89% · P56

影响版本矩阵 1

厂商产品版本范围状态
n/an/an/aaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-25262 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Stimulsoft GmbH Stimulsoft Designer 代码问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Stimulsoft GmbH Stimulsoft Designer是Stimulsoft公司的一款可在任何计算机和任何平台上运行的坚固产品。用于生成报表和分析数据的引擎、报表设计器和查看器。 Stimulsoft Designer (Web) 2023.1.3版本存在安全漏洞,该漏洞源于TThe Reporting Designer (Web) 提供了从外部位置嵌入源的可能性,攻击者利用该漏洞可以在托管 Stimulsoft Reporting Designer (Web) 的服务器的内部网络上泄露机
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
-n/a n/a -

二、漏洞 CVE-2023-25262 的公开POC

#POC 描述源链接神龙链接
1Nonehttps://github.com/trustcves/CVE-2023-25262POC详情
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-25262 的情报信息

登录查看更多情报信息。

CVE-2023-25262 安全博客文章 (1)

CVE-2023-25262 其他参考 (2)

同批安全公告 · n/a · 2023-03-28 · 共 28 条

CVE-2023-16767.8 HIGHDriverGenius 缓冲区错误漏洞
CVE-2023-16775.5 MEDIUMDriverGenius 安全漏洞
CVE-2023-16785.3 MEDIUMCmcm Drivergenius 缓冲区错误漏洞
CVE-2023-16795.3 MEDIUMDriverGenius 缓冲区错误漏洞
CVE-2023-27821Databasir 安全漏洞
CVE-2023-27701MuYuCMS 安全漏洞
CVE-2023-27700MuYuCMS 路径遍历漏洞
CVE-2023-27247Cynet Client Agent 安全漏洞
CVE-2023-27246MK-Auth 代码问题漏洞
CVE-2023-27232TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27231TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27229TOTOLINK A7100RU 命令注入漏洞
CVE-2023-27008ATutor 跨站脚本漏洞
CVE-2023-26923Musescore 缓冲区错误漏洞
CVE-2023-26071MCUBO ICT 安全漏洞
CVE-2023-25722Jenkins Plugin Veracode Scan 安全漏洞
CVE-2023-25721Jenkins Plugin Veracode Scan 安全漏洞
CVE-2023-25260Stimulsoft 安全漏洞
CVE-2023-24308PDF-XChange Editor 安全漏洞
CVE-2023-24304IrfanView 输入验证错误漏洞

显示前 20 条,共 28 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-25262

暂无评论


发表评论