CVE-2024-52270 is a User Interface Misrepresentation vulnerability in Dropbox Sign (HelloSign) that allows content spoofing by failing to flatten all layers when a document is printed, even if the displayed version appears flattened. This vulnerability, affecting versions through 2024-12-04, has a high CVSS score of 8.2 due to its potential for high integrity impact through user interaction. While the attack vector is local and requires user interaction, it can lead to critical information being misrepresented in printed documents. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DropBox(HelloSign) | DropBox Sign | >= 0, <= 2024-12-04CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.