Summary of Vulnerabilities in StreamSoft Prestiż
On March 28, 2025, CERT Polska reported two significant vulnerabilities in the StreamSoft Prestiż software, a product from Streamsoft, affecting various versions of the application prior to specific updates.
Vulnerability Details
-
CVE-2024-11504
- Description: This vulnerability stems from the inadequate sanitization of inputs across multiple fields in StreamSoft Prestiż. It allows for SQL injection attacks, enabling remote authenticated attackers to manipulate database queries, potentially leading to unauthorized data access or alterations. The flaw was notable for affecting all versions released before 18.1.376.37.
- Resolution: The issue was addressed in version 18.1.376.37, which incorporated better input handling to prevent such exploitation.
- CVE-2024-7407
- Description: The second vulnerability involves the use of a weak custom password encoding algorithm in the Prestiż software. This flaw allows attackers to decode or brute-force stored user passwords, compromising user security. Similar to the first vulnerability, this issue affects all versions released before 18.2.377.
- Resolution: A fix for this vulnerability was implemented in version 18.2.377, which updated the password handling to utilize more secure encoding practices.
Reporting and Acknowledgment
CERT Polska played a crucial role in the identification and coordination of the disclosure process for these vulnerabilities. The organization emphasized the importance of responsible vulnerability reporting, highlighting Kamil Dąbkowski’s efforts in informing about these security weaknesses.
Conclusion
Both vulnerabilities underscore the significance of robust input validation and secure password handling protocols in software development. Users of the StreamSoft Prestiż application are strongly encouraged to update their systems to the latest versions (18.1.376.37 and 18.2.377, respectively) to mitigate potential security risks.
For additional information regarding the coordinated vulnerability disclosure process at CERT Polska, users can visit their website at cert.pl/en/cvd/.
In light of the increasing reliance on digital systems and applications, the responsibility for securing software from vulnerabilities is paramount for both developers and users. Upgrading to the latest software versions and adhering to best practices in cybersecurity can significantly reduce the risk of exploitation from vulnerabilities like those disclosed in StreamSoft Prestiż. This incident serves as a reminder for organizations to regularly audit their software for vulnerabilities, secure sensitive user data, and maintain open channels for reporting and addressing potential security risks.