CyberRota Analysis
AI-GeneratedOpenSignLabs OpenSign versions up to 2.37.0 are vulnerable due to an insecure direct object reference that permits unauthenticated remote attackers to modify any contact record through the updatecontacttour Parse cloud function, which lacks proper authentication and authorization checks. This vulnerability allows attackers to corrupt or overwrite contact data for any user, posing significant risks to data integrity and privacy. Organizations using this software should prioritize patching this vulnerability to prevent unauthorized data manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials.