Required CVE Record Information
Description
User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
8.2 | HIGH | 4.0 | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/U:Red |
Product Status
Learn moreVersions 2 Total
Default Status: affected
affected
Versions 2 Total
Default Status: affected
affected
Credits
- Erez Kalman finder
References 4 Total
- https://www.vulsec.org/advisories vdb-entry
- https://github.com/documenso/documenso product
- https://www.documenso.com/ product
- https://github.com/documenso/documenso/issues/1512 issue-tracking