CyberRota Analysis
AI-GeneratedOpenSignLabs OpenSign versions up to 2.37.0 are vulnerable to an integrity verification flaw that permits unauthenticated remote attackers to manipulate document audit-trail entries through the triggerevent Parse cloud function. This vulnerability enables the fabrication of arbitrary audit log entries, compromising the integrity and non-repudiation of signed documents. Organizations utilizing OpenSign for document management should prioritize patching this vulnerability to protect against potential legal and compliance ramifications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.