CVE-2024-52270
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
05/12/2024
Last modified:
05/12/2024
Description
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing.<br />
Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.<br />
This issue affects DropBox Sign(HelloSign): through 2024-12-04.
References to Advisories, Solutions, and Tools
- https://app.hellosign.com/
- https://drive.proton.me/urls/Z6DHXNRZQC#jkfO38rjOiOj
- https://new.space/s/ZuHoujvkjdzfY7Uihah7Yg#SKWLU_g2Cihfj4qsq9XNy6F4saxVAzD876PujiDOYfs
- https://sign.dropbox.com/
- https://www.loom.com/share/48f63594e14c49e19840ad9cb7d60453?sid=816c6afa-0b67-4b0b-98ff-d5c58d464038
- https://www.vulsec.org/advisories



