NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
Weakness
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
References