Junglewise Threat Intelligence

CVE-2025-10727: ArkSigner AcBakImzala Reflected XSS

CVE-2025-10727 · Severity: medium · CVSS 5.4 · Published 2025-10-23

Executive brief

ArkSigner AcBakImzala, a software solution used for digital signature processes, contains a security vulnerability that could allow an attacker to execute malicious scripts in a user's browser. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions being performed on the user's behalf within the application. While it does not directly expose the underlying database, it can disrupt the integrity of the user's session and the application's interface.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in ArkSigner AcBakImzala versions prior to v5.1.4. The application fails to properly sanitize or neutralize input provided by users before including it in dynamically generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a victim into visiting a malicious URL containing executable script code. If successful, the script executes within the context of the victim's browser session, allowing for session hijacking or unauthorized manipulation of the web interface. The issue is addressed in version 5.1.4.

Affected products

  • ArkSigner Software and Hardware Inc. AcBakImzala before v5.1.4

Timeline

  • 2025-10-23: advisory: Initial publication of the vulnerability details.
  • 2025-10-23: disclosed: Vulnerability reported by the Computer Emergency Response Team of the Republic of Turkey.

References

Related threats