漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Documenso - Assistant Recipient Can Forge Another Signer's Signature in Sequential-Signing Documents
Vulnerability Description
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Documenso 授权问题漏洞
Vulnerability Description
Documenso是Documenso团队开源的一款数字文档签署平台。 Documenso存在授权问题漏洞,该漏洞源于sign-field-with-token.ts文件对字段类型和所有权验证不足,可能导致具有ASSISTANT角色的接收者获取并完成同一信封中后续未签名接收者的字段,从而伪造其他签名者的签名字段。
CVSS Information
N/A
Vulnerability Type
N/A