Impact
The vulnerability is an integrity verification flaw in OpenSign's triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller‑supplied parameters without any authentication checks, which allows an unauthenticated remote attacker to forge entries into the document audit trail. By forging audit log entries, an attacker can alter the legal record of any signed document, effectively compromising non‑repudiation and the integrity of the audit trail.
Affected Systems
OpenSignLabs’ OpenSign up to version 2.37.0 is affected. Any installations of OpenSign 2.37.0 or earlier are vulnerable; later releases are not impacted as of the current data.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is not available, so the likelihood of exploitation cannot be quantified at present. The vulnerability is not listed in CISA KEV. The attack vector is remote and requires the attacker to invoke the triggerevent Parse cloud function, supplying arbitrary viewer identity and IP address values; no authentication is required, making exploitation straightforward for anyone able to reach the function.
OpenCVE Enrichment