Impact
proCertum SmartSign fails to restrict XML External Entity references when parsing signature files. An attacker can craft an XML file containing an external entity that resolves to a local file or a remote internal host. The vulnerability is triggered simply by previewing the file in the file selection window, before the user clicks “Open”, allowing the application to read the referenced content or perform a Server Side Request Forgery. The impact is limited to data exfiltration of local files or internal network resources; no arbitrary code execution is possible according to the description.
Affected Systems
Users of Asseco proCertum SmartSign whose installations are older than version 9.4.3.90 are vulnerable. No other vendors or products are listed in the CVE data.
Risk and Exploitability
The assessment score of 4.8 indicates a moderate severity. Exploitation requires an attacker to supply a malicious XML file and to convince a legitimate user to preview it, suggesting social‑engineering or supply‑chain vectors. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. While the attack does not grant executable code, the possibility of reading confidential files or making internal network requests warrants prompt action.
OpenCVE Enrichment