User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.
History

Thu, 05 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L'}


Thu, 05 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:documenso:documenso_saas\/hosted\/:*:*:*:*:*:*:*:* cpe:2.3:a:documenso:documenso:*:*:*:*:saas:*:*:*
Vendors & Products Documenso documenso Saas\/hosted\/

Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Documenso
Documenso documenso
Documenso documenso Saas\/hosted\/
CPEs cpe:2.3:a:documenso:documenso:*:*:*:*:*:*:*:*
cpe:2.3:a:documenso:documenso_saas\/hosted\/:*:*:*:*:*:*:*:*
Vendors & Products Documenso
Documenso documenso
Documenso documenso Saas\/hosted\/
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 14:00:00 +0000

Type Values Removed Values Added
Description User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.
Title PDF Document Spoofing in Documenso
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VULSec

Published:

Updated: 2024-12-05T16:53:23.959Z

Reserved: 2024-11-06T08:35:09.852Z

Link: CVE-2024-52271

cve-icon Vulnrichment

Updated: 2024-12-05T14:23:08.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-05T14:15:21.417

Modified: 2024-12-05T17:15:12.927

Link: CVE-2024-52271

cve-icon Redhat

No data.