Impact
An unauthenticated remote attacker can invoke the getUserId Parse cloud function in OpenSignLabs OpenSign through version 2.37.0 to map an email address or username to the internal user objectId. Because the function performs no authentication before resolving and returning the identifier, the attacker may enumerate all user accounts and, subsequently, target them with more specific attacks. This vulnerability directly manifests as information disclosure and aligns with CWE‑200.
Affected Systems
OpenSignLabs OpenSign, versions up to and including 2.37.0 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, but the exposed network endpoint allows unauthenticated remote enumeration. While confidentiality or integrity are not immediately compromised, the mapping of internal identifiers can aid later phishing or credential‑guessing attacks. Given the lack of a known exploit and the moderate score, the risk is present but not acute; prompt remediation is advised.
OpenCVE Enrichment