Description
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.


This issue affects DocuSeal: through 1.8.1, >1.8.1.
Published: 2024-12-04
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

* If other party initiated e-signing - Download the PDF file for a security professionals/educated persons inspection * If possible - Download the PDF file and perform full flattening (of the entire document, not just form fields)

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-46118 User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DocuSeal: through 1.8.1, >1.8.1.
History

Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Docuseal
Docuseal docuseal
CPEs cpe:2.3:a:docuseal:docuseal:-:*:*:*:*:*:*:*
Vendors & Products Docuseal
Docuseal docuseal
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 13:45:00 +0000

Type Values Removed Values Added
Description User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.This issue affects DocuSeal: through 1.8.1, >1.8.1. User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DocuSeal: through 1.8.1, >1.8.1.

Wed, 04 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 12:45:00 +0000


Wed, 04 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
Description ** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing.This issue affects [WITHHELD]: through [WITHHELD]. User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.This issue affects DocuSeal: through 1.8.1, >1.8.1.
Title PDF Document Spoofing in [WITHHELD] PDF Document Spoofing in DocuSeal

Wed, 04 Dec 2024 10:30:00 +0000

Type Values Removed Values Added
Description ** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing.This issue affects [WITHHELD]: through [WITHHELD].
Title PDF Document Spoofing in [WITHHELD]
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/U:Red'}


Subscriptions

Docuseal Docuseal
cve-icon MITRE

Status: PUBLISHED

Assigner: VULSec

Published:

Updated: 2024-12-05T16:50:47.391Z

Reserved: 2024-11-06T08:35:09.853Z

Link: CVE-2024-52277

cve-icon Vulnrichment

Updated: 2024-12-04T19:07:01.033Z

cve-icon NVD

Status : Received

Published: 2024-12-04T11:30:51.107

Modified: 2024-12-05T14:15:21.547

Link: CVE-2024-52277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses