proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”.
This issue was fixed in version 9.4.3.90.
CVSS
No CVSS.
References
Configurations
No configuration.
History
27 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-27 12:16
Updated : 2026-07-30 16:29
NVD link : CVE-2026-57917
Mitre link : CVE-2026-57917
CVE.ORG link : CVE-2026-57917
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
