Dos vulnerabilidades en el software StreamSoft Prestiż

Summary of Vulnerabilities in StreamSoft Prestiż

On March 28, 2025, CERT Polska reported two significant vulnerabilities in the StreamSoft Prestiż software, a product from Streamsoft, affecting various versions of the application prior to specific updates.

Vulnerability Details

  1. CVE-2024-11504

    • Description: This vulnerability stems from the inadequate sanitization of inputs across multiple fields in StreamSoft Prestiż. It allows for SQL injection attacks, enabling remote authenticated attackers to manipulate database queries, potentially leading to unauthorized data access or alterations. The flaw was notable for affecting all versions released before 18.1.376.37.
    • Resolution: The issue was addressed in version 18.1.376.37, which incorporated better input handling to prevent such exploitation.
  2. CVE-2024-7407
    • Description: The second vulnerability involves the use of a weak custom password encoding algorithm in the Prestiż software. This flaw allows attackers to decode or brute-force stored user passwords, compromising user security. Similar to the first vulnerability, this issue affects all versions released before 18.2.377.
    • Resolution: A fix for this vulnerability was implemented in version 18.2.377, which updated the password handling to utilize more secure encoding practices.

Reporting and Acknowledgment

CERT Polska played a crucial role in the identification and coordination of the disclosure process for these vulnerabilities. The organization emphasized the importance of responsible vulnerability reporting, highlighting Kamil Dąbkowski’s efforts in informing about these security weaknesses.

Conclusion

Both vulnerabilities underscore the significance of robust input validation and secure password handling protocols in software development. Users of the StreamSoft Prestiż application are strongly encouraged to update their systems to the latest versions (18.1.376.37 and 18.2.377, respectively) to mitigate potential security risks.

For additional information regarding the coordinated vulnerability disclosure process at CERT Polska, users can visit their website at cert.pl/en/cvd/.


In light of the increasing reliance on digital systems and applications, the responsibility for securing software from vulnerabilities is paramount for both developers and users. Upgrading to the latest software versions and adhering to best practices in cybersecurity can significantly reduce the risk of exploitation from vulnerabilities like those disclosed in StreamSoft Prestiż. This incident serves as a reminder for organizations to regularly audit their software for vulnerabilities, secure sensitive user data, and maintain open channels for reporting and addressing potential security risks.

Enlace de la fuente, haz clic para tener más información

Artículos y alertas de seguridad

Consultar más contenidos y alertas

Alertas y noticias de seguridad de la información

Contacta

Contacta con nosotros para obtener soluciones integrales en IT y seguridad de la información

Estamos encantados de responder cualquier pregunta que puedas tener, y ayudarte a determinar cuáles de nuestros servicios se adaptan mejor a tus necesidades.

Nuestros beneficios:
¿Qué sucede a continuación?
1

Programamos una llamada según tu conveniencia.

2

Realizamos una reunión de descubrimiento y consultoría.

3

Preparamos una propuesta.

Agenda una consulta gratuita