This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46112 | User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05. |
Solution
No solution given by the vendor.
Workaround
* If other party initiated e-signing - Download the PDF file for a security professionals/educated persons inspection * If possible - Download the PDF file and perform full flattening (of the entire document, not just form fields)
Thu, 05 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 05 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:documenso:documenso:*:*:*:*:saas:*:*:* | |
| Vendors & Products |
Documenso documenso Saas\/hosted\/
|
Thu, 05 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Documenso
Documenso documenso Documenso documenso Saas\/hosted\/ |
|
| CPEs | cpe:2.3:a:documenso:documenso:*:*:*:*:*:*:*:* cpe:2.3:a:documenso:documenso_saas\/hosted\/:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Documenso
Documenso documenso Documenso documenso Saas\/hosted\/ |
|
| Metrics |
cvssV3_1
|
Thu, 05 Dec 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05. | |
| Title | PDF Document Spoofing in Documenso | |
| Weaknesses | CWE-451 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VULSec
Published:
Updated: 2024-12-05T16:53:23.959Z
Reserved: 2024-11-06T08:35:09.852Z
Link: CVE-2024-52271
Updated: 2024-12-05T14:23:08.497Z
Status : Awaiting Analysis
Published: 2024-12-05T14:15:21.417
Modified: 2024-12-05T17:15:12.927
Link: CVE-2024-52271
No data.
OpenCVE Enrichment
No data.
EUVD