Executive brief
Netcad NetGIS, a geographic information system platform, contains a security flaw in how it processes data. An attacker can exploit this to remotely access sensitive files or internal network resources that should be protected. This could lead to the exposure of confidential organizational data or mapping information.
Technical details
An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists in Netcad NetGIS versions 5.0.66 through 7.2.2. The vulnerability is rooted in the application's handling of serialized data and XML input, which fails to properly restrict external entity references. A remote, unauthenticated attacker can exploit this over the network by sending a specially crafted XML payload. Successful exploitation allows the attacker to read local files, perform server-side request forgery (SSRF), or cause a denial-of-service condition. The issue is addressed in version 7.2.2.
Affected products
- Netcad Software Inc. NetGIS 5.0.66 to 7.2.2
Timeline
- 2026-07-17: advisory: Published by TR-CERT and NVD