PT-2026-70124 · Opensignlabs · Opensign
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSignLabs OpenSign versions prior to 2.37.1
Description
An information disclosure issue exists where unauthenticated remote attackers can map any email address or username to its internal user
objectId via the getUserId() Parse cloud function. The function fails to perform authentication before resolving and returning the internal identifier, which allows for the enumeration of user accounts to facilitate subsequent attacks.Recommendations
Update OpenSignLabs OpenSign to version 2.37.1 or later.
As a temporary workaround, restrict access to the
getUserId() function until the update is applied.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign