PT-2026-26284 · Slovensko.Digital · Autogram
Martin Orem
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-3511
CVSS v3.1
8.6
High
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autogram