PT-2024-35146 · Docusign · Docusign
Erez Kalman
·
Published
2024-12-04
·
Updated
2025-01-06
·
CVE-2024-52276
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DocuSign versions through 2024-12-04
Description
The issue is related to a User Interface (UI) Misrepresentation of Critical Information vulnerability, which allows Content Spoofing. This means that the displayed version of a document does not accurately represent the actual content, specifically when using the "Print" option, combined download option, or uncombined download option. The vulnerability can be observed when printing the document, for example, via Google Chrome's print preview, where only the vulnerable content is rendered, and not all layers are flattened.
Recommendations
For DocuSign versions through 2024-12-04, update to a version released after 2024-12-04 to mitigate the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docusign