Impact
A failure to enforce authentication or authorization in OpenSignLabs OpenSign allows remote attackers to invoke the updatecontacttour cloud function and write to any contact record. The vulnerability, identified as an insecure direct object reference (CWE‑639), enables an attacker to corrupt or overwrite personal data for any user without credentials, undermining data integrity and potentially exposing sensitive information.
Affected Systems
The flaw exists in all releases of OpenSignLabs OpenSign through version 2.37.0. Any deployment of those versions that exposes the updatecontacttour service is affected.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified, but the function is remotely accessible and requires no authentication, making exploitation straightforward. The vulnerability is not listed in the CISA KEV catalog, yet its reach to all contact records warrants urgent mitigation.
OpenCVE Enrichment