PT-2026-2375 · Geonetwork+2 · Geonetwork+1

·

CVE-2022-50899

·

Published

2026-01-13

·

Updated

2026-02-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Geonetwork versions 3.10 through 4.2.0
Description Geonetwork contains a flaw in its PDF rendering process related to XML external entities. This allows attackers to retrieve arbitrary files from the server. The issue stems from an insecure XML parser that can be exploited by crafting malicious XML documents with external entity references. Specifically, attackers can read system files through the baseURL parameter when making PDF creation requests.
Recommendations Versions prior to 4.2.1 should be updated.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50899

Affected Products

Geonetwork
Core-Geonetwork