CVE-2023-25260

HIGH

Stimulsoft Designer (Web) 2023.1.3 - Local File Inclusion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-25260. PoCs published by trustcves.

AI-analyzed exploit summary This repository contains a detailed technical writeup for CVE-2023-25260, a Local File Inclusion (LFI) vulnerability in Stimulsoft Designer (Web) versions 2023.1.3 and 2023.1.4. The writeup includes a proof of concept demonstrating how arbitrary local files can be read by manipulating the datasource file path input.

Description

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

Exploits (1)

nomisec WRITEUP
by trustcves · poc
https://github.com/trustcves/CVE-2023-25260

This repository contains a detailed technical writeup for CVE-2023-25260, a Local File Inclusion (LFI) vulnerability in Stimulsoft Designer (Web) versions 2023.1.3 and 2023.1.4. The writeup includes a proof of concept demonstrating how arbitrary local files can be read by manipulating the datasource file path input.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Stimulsoft Designer (Web) 2023.1.3, 2023.1.4
No auth needed
Prerequisites: Access to the Stimulsoft Designer (Web) interface · Knowledge of the server's file system structure
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0100
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (2)
stimulsoft/designer 2023.1.3
stimulsoft/designer 2023.1.4
Published Mar 28, 2023
Tracked Since Feb 18, 2026