PT-2022-11683 · Stimulsoft · Stimulsoft Reports

Burninator

·

Published

2022-10-29

·

Updated

2022-11-01

·

CVE-2021-42777

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Stimulsoft (aka Stimulsoft Reports) version 2013.1.1600.0
Description The issue allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine. This is demonstrated by the use of System.Diagnostics.Process.Start.
Recommendations For Stimulsoft (aka Stimulsoft Reports) version 2013.1.1600.0, consider disabling the Compilation Mode as a temporary workaround until a patch is available. Restrict access to sensitive reports and machines to minimize the risk of exploitation. Avoid using the System.Diagnostics.Process.Start function in reports until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-42777

Affected Products

Stimulsoft Reports