← Zuruck zu CVEs
CVE-2026-3511
HIGH8.6
Beschreibung
Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application.
CVE Details
CVSS v3.1 Bewertung8.6
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/19/2026
Zuletzt geandert3/19/2026
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-611
Referenzen
https://blog.binary.house/2026/03/pripadova-studia-ako-sme-s-claude-code.html(incident@nbu.gov.sk)
https://github.com/slovensko-digital/autogram/releases/tag/v2.7.2(incident@nbu.gov.sk)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.