Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-56218 — Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing links to be converted to PDF and distributed, with CVSS 5.5 and mitigation guidance. | Kitploit
Tools/GitHubGitHub/saykino/cve-2025-56218
Vulnerability AnalysisPhishingWeb SecurityLearning & EducationCurated Resources
GitHubsaykino/cve-2025-56218

CVE-2025-56218

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing links to be converted to PDF and distributed, with CVSS 5.5 and mitigation guidance.

View Repository
10 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-56218 Unrestricted File Upload

Description

An attacker may upload an Excel file that contains a malicious script or a phishing URL. The application converts the file to PDF and forwards it to the intended recipient for digital signature. Because hyperlinks in the generated PDF are displayed with attacker-controlled text and no warning is presented, the recipient could be deceived into clicking the link and thereby triggering execution of malicious commands


CVSS Score: 5.5 (Medium)


Attack Type

  • Remote (Authenticated)

Affected Versions

  • versions before <= 8.6.8

Vendor of Product

  • Ascertia

Affected Product Code Base

  • SigningHub

Affected Component

  • File Upload Function.

Mitigations

  • Scan the uploaded file before sending it to the target users

Vulnerability Details

  • An attacker can upload a file containing malicious website/script and send it to a list of users. Through social engineering, users may be directed to the attacker’s phishing website, as the application does not scan uploaded file contents.

Fixed versions

  • versions after > 8.6.8

Discovered By:

  • Yazan Abu-Nadi
Download Tool