PT-2026-64889 · Procertum · Smartsign
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
proCertum SmartSign versions prior to 9.4.3.90
Description
proCertum SmartSign parses external XML entities from crafted signature files, which enables Server-Side Request Forgery (SSRF) and potentially allows the reading of local files, depending on the parser's configuration. This XML External Entity (XXE) issue is triggered when a user previews a file in the file selection window, occurring before the file is actually opened.
Recommendations
Update to version 9.4.3.90.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartsign