
Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing links to be converted to PDF and distributed, with CVSS 5.5 and mitigation guidance.
An attacker may upload an Excel file that contains a malicious script or a phishing URL. The application converts the file to PDF and forwards it to the intended recipient for digital signature. Because hyperlinks in the generated PDF are displayed with attacker-controlled text and no warning is presented, the recipient could be deceived into clicking the link and thereby triggering execution of malicious commands
Attack Type
Affected Versions
Vendor of Product
Affected Product Code Base
Affected Component
Mitigations
Vulnerability Details
Fixed versions
Discovered By: