In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Designer | Stimulsoft | 2023.1.4 (including) | 2023.1.4 (including) |
Designer | Stimulsoft | 2023.1.5 (including) | 2023.1.5 (including) |