Impact
The vulnerability is an XML external entity (XXE) flaw that permits NetGIS to resolve external entities in serialized XML data that it processes. Because the application does not limit external entity references, an attacker can supply a crafted XML payload that triggers the fetch of arbitrary files, network resources, or potentially executable payloads, enabling sensitive data exposure. Based on the description, it is inferred that remote code execution may be possible, though no evidence is publicly documented. This weakness is classified as CWE‑611.
Affected Systems
Netcad Software Inc.’s NetGIS product is affected for versions starting at 5.0.66 up to, but not including, 7.2.2. The vulnerability can impact any module that accepts XML input, such as network mapping, GIS mapping, or document handling components within the NetGIS platform.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote: a malicious actor could send a specially crafted XML file to the NetGIS service, thereby exploiting the unprotected external entity handling. The impact would likely be data exfiltration and, based on the description, it is inferred that remote code execution may be possible, though no evidence of exploitation is publicly documented.
OpenCVE Enrichment