← volver
CVE-2024-52270highexplotación observadaCWE-451

PDF Document Spoofing in DropBox Sign(HelloSign)

43Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Actcvss 8.2epss 0.2%
de la publicación al arma
Publicada en NVD5 dic
VulnCheck5 dic
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
VulnCheck
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/AU:Y/U:Red