CVE-2024-52276 is a User Interface Misrepresentation vulnerability in DocuSign, affecting versions through 2024-12-04, that allows content spoofing. It occurs because the displayed document version does not accurately reflect the flattened layer version provided when printing or downloading, potentially hiding critical information. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact, but no integrity or availability impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DocuSign | DocuSign | >= 0, <= 2024-12-04CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.