PT-2024-35146 · Docusign · Docusign

Erez Kalman

·

Published

2024-12-04

·

Updated

2025-01-06

·

CVE-2024-52276

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DocuSign versions through 2024-12-04
Description The issue is related to a User Interface (UI) Misrepresentation of Critical Information vulnerability, which allows Content Spoofing. This means that the displayed version of a document does not accurately represent the actual content, specifically when using the "Print" option, combined download option, or uncombined download option. The vulnerability can be observed when printing the document, for example, via Google Chrome's print preview, where only the vulnerable content is rendered, and not all layers are flattened.
Recommendations For DocuSign versions through 2024-12-04, update to a version released after 2024-12-04 to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2024-52276

Affected Products

Docusign