Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fw3-pvfm-qmmq

Опубликовано: 05 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.

EPSS

Процентиль: 13%
0.00044
Низкий

8.2 High

CVSS4

Дефекты

CWE-451

Связанные уязвимости

nvd
около 1 года назад

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.

EPSS

Процентиль: 13%
0.00044
Низкий

8.2 High

CVSS4

Дефекты

CWE-451