PT-2026-70123 · Opensignlabs · Opensign
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSignLabs OpenSign versions prior to 2.37.1
Description
An information disclosure issue exists where unauthenticated remote attackers can retrieve organization tenant records. This is possible through the
gettenant Parse cloud function, which accepts a contactId parameter and returns the full tenant record without performing authentication or authorization checks. This allows for the enumeration and disclosure of tenant configuration data for any organization within the system.Recommendations
Update OpenSignLabs OpenSign to version 2.37.1 or later.
As a temporary workaround, restrict access to the
gettenant function to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign