Impact
An unauthenticated remote attacker can invoke the gettenant Parse cloud function within OpenSignLabs OpenSign through version 2.37.0. The function accepts a contactId parameter and, without authentication or authorization checks, returns the full tenant record, exposing confidential configuration data. This information disclosure can reveal sensitive attributes such as tenant setup, contact details, and system settings, compromising the confidentiality of all organisations using the application. The weakness is an instance of CWE‑200.
Affected Systems
The impact applies to OpenSignLabs OpenSign, specifically all versions up to and including 2.37.0. Deployments running any of these affected releases are susceptible; newer versions are presumed corrected pending vendor release.
Risk and Exploitability
The CVSS score of 7.5 indicates a high overall risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote via the public API; an attacker only needs to craft a request to a recognized endpoint and supply a contactId, which can be enumerated. Successful exploitation yields the full tenant record, potentially exposing a wide range of organisational data. Because no authentication is required, the threat persists until the software is updated or mitigated.
OpenCVE Enrichment