proCertum SmartSign 会解析来自任意构造的签名文件中的外部 XML 实体,从而导致服务器端请求伪造(SSRF),并可能在特定解析器配置下允许读取本地文件。该 XML 外部实体(XXE)漏洞仅在用户在文件选择窗口中预览文件时即可触发,无需受害者点击“打开”按钮。 此问题已在版本 9.4.3.90 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Asseco | proCertum SmartSign | < 9.4.3.90 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Asseco | proCertum SmartSign | 0 ~ 9.4.3.90 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet