Executive brief
proCertum SmartSign, a software tool used for creating and verifying electronic signatures, is vulnerable to a security flaw when handling signature files. An attacker can create a malicious file that, when simply previewed by a user in the file selection window, could allow the attacker to view sensitive local files or perform unauthorized network requests. This could lead to the exposure of private data or internal network information.
Technical details
An XML External Entity (XXE) vulnerability (CWE-611) exists in Asseco proCertum SmartSign due to improper restriction of external entity references in its XML parser. The vulnerability is triggered when the application processes a crafted signature file, notably occurring during the file preview stage in the file selection dialog before the user even clicks 'Open'. A local attacker or an attacker who can convince a user to interact with a malicious file can achieve Server-Side Request Forgery (SSRF) or read local files, depending on the specific parser configuration. The issue is resolved in version 9.4.3.90.
Affected products
- Asseco Data Systems proCertum SmartSign All versions prior to 9.4.3.90
Timeline
- 2026-07-27: advisory: Initial disclosure by CERT.PL
- 2026-07-27: patched: Fix released in version 9.4.3.90