User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. For reference see: CVE-2024-52276 This issue affects DocuSign: through 2024-12-04.
History

Mon, 06 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Docusign
Docusign docusign
CPEs cpe:2.3:a:docusign:docusign:-:*:*:*:*:*:*:*
Vendors & Products Docusign
Docusign docusign
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 10:45:00 +0000

Type Values Removed Values Added
Description ** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. This issue affects [WITHHELD]: through 2024-12-04. User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. For reference see: CVE-2024-52276 This issue affects DocuSign: through 2024-12-04.
Title AI Assistant PDF Document Spoofing in [WITHHELD] AI Assistant PDF Document Spoofing in DocuSign
References

Wed, 04 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 11:30:00 +0000

Type Values Removed Values Added
Description ** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. This issue affects [WITHHELD]: through 2024-12-04.
Title AI Assistant PDF Document Spoofing in [WITHHELD]
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VULSec

Published: 2024-12-04T11:25:45.886Z

Updated: 2025-01-06T17:39:56.341Z

Reserved: 2024-11-06T08:35:09.852Z

Link: CVE-2024-52269

cve-icon Vulnrichment

Updated: 2024-12-04T14:39:08.492Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-04T12:15:19.500

Modified: 2025-01-06T18:15:20.720

Link: CVE-2024-52269

cve-icon Redhat

No data.