CVE-2023-25262

HIGH

Stimulsoft Designer 2023.1.3 - Server-Side Request Forgery via External Resource Embedding

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-25262. PoCs published by trustcves.

AI-analyzed exploit summary This repository contains a detailed technical writeup describing an SSRF vulnerability in Stimulsoft Designer (Web) 2023.1.3, where the server performs outbound requests to external locations when importing files, potentially leading to data exfiltration. The writeup includes a proof of concept, vendor communication timeline, and technical details about the vulnerability.

Description

Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).

Exploits (1)

nomisec WRITEUP
by trustcves · poc
https://github.com/trustcves/CVE-2023-25262

This repository contains a detailed technical writeup describing an SSRF vulnerability in Stimulsoft Designer (Web) 2023.1.3, where the server performs outbound requests to external locations when importing files, potentially leading to data exfiltration. The writeup includes a proof of concept, vendor communication timeline, and technical details about the vulnerability.

Classification
Writeup 100%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: Stimulsoft Designer (Web) 2023.1.3
No auth needed
Prerequisites: Access to the Stimulsoft Designer (Web) interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory
http://stimulsoft.com
Exploit, Third Party Advisory
https://cves.at/posts/cve-2023-25262/writeup/

Scores

CVSS v3 7.5
EPSS 0.0108
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
stimulsoft/designer 2023.1.3
stimulsoft/designer 2023.1.4
Published Mar 28, 2023
Tracked Since Feb 18, 2026