proCertum SmartSign 在未进行模式验证的情况下打开了证书实践声明(CPS)统一资源标识符(URI)。攻击者可以构造一个任意证书,其 CPS URI 指向一个本地可执行文件或其他任意 URL,并用该证书对文档进行签名,然后将该文档发送给受害者。当受害者在应用程序中打开此文档时,指定的文件将被执行(或网页将被打开)。 此问题已在版本 9.4.3.90 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Asseco | proCertum SmartSign | < 9.4.3.90 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Asseco | proCertum SmartSign | 0 ~ 9.4.3.90 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet