PT-2024-35140 · Docusign · Docusign

Erez Kalman

·

Published

2024-12-04

·

Updated

2025-01-06

·

CVE-2024-52269

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DocuSign versions through 2024-12-04
Description The issue concerns a User Interface (UI) Misrepresentation of Critical Information vulnerability that allows Content Spoofing. Specifically, the SaaS AI assistant ignores hidden content that is rendered after signing, which can mislead the user.
Recommendations For DocuSign versions through 2024-12-04, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2024-52269

Affected Products

Docusign