PT-2026-70119 · Opensignlabs · Opensign
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSignLabs OpenSign versions prior to 2.37.1
Description
An integrity verification issue allows unauthenticated remote attackers to forge document audit-trail entries. This is possible through the
triggerevent Parse cloud function, which accepts viewer identity and IP address as caller-supplied parameters without authentication. By exploiting this, an attacker can fabricate arbitrary audit log entries and tamper with the legal audit trail of any signed document, undermining non-repudiation, which is the assurance that someone cannot deny the validity of something.Recommendations
Update OpenSignLabs OpenSign to version 2.37.1 or later.
As a temporary workaround, restrict access to the
triggerevent Parse cloud function to minimize the risk of exploitation.Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign