PT-2024-35147 · Google · Google Chrome

Erez Kalman

·

Published

2024-12-04

·

Updated

2024-12-05

·

CVE-2024-52277

CVSS v4.0

8.2

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
Name of the Vulnerable Software and Affected Versions DocuSeal versions through 1.8.1
Description The issue is related to a User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal, allowing Content Spoofing. This means that the displayed version of a document does not accurately show the layer flattened version. When the document is downloaded and printed, for example via Google Chrome's print preview, it will render the vulnerability, but not all layers are flattened.
Recommendations For versions through 1.8.1, update to a version that addresses this issue to prevent Content Spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2024-52277

Affected Products

Google Chrome