Impact
The identified vulnerability is an improper restriction of XML external entity references in the ministry’s UYAP Document Editor. This flaw allows an attacker to embed serialized data external links within an XML document, potentially enabling the reading of arbitrary local files or the execution of remote code if the editor processes such entities. Consequently, confidential information could be exfiltrated, and in certain configurations may lead to further exploitation such as remote code execution.
Affected Systems
The Ministry of Justice’s UYAP Document Editor versions 4.5.17 through the release just prior to 5.4.17 are affected. This includes all builds from 4.5.17 up to 5.4.16 (inclusive).
Risk and Exploitability
The CVSS score of 6.3 classifies the vulnerability as medium severity, suggesting noticeable risk without immediate guarantee of exploitation. Exploitability requires an attacker to submit a maliciously crafted XML document via the document editor interface, meaning network exposure of or legitimate use of the editor is a prerequisite. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment