Home
CRITICAL: 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
2.0.3 (custom)
affected
2.5.5
unaffected
Description
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
Product status
2.0.3 (custom)
2.5.5
Credits
Marek Alakša of Binary House
References
www.disig.sk/...ortant-update-of-the-web-signer-application/
www.disig.sk/.../dolezita-aktualizacia-aplikacie-web-signer/
download.disigcdn.sk/...products/websigner2/changelog.en.txt
download.disigcdn.sk/...products/websigner2/changelog.sk.txt
qesportal.sk/Portal/en/Info/News
qesportal.sk/Portal/sk/Info/News