Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Documenso - Assistant Recipient Can Forge Another Signer's Signature in Sequential-Signing Documents
Vulnerability Description
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Documenso 授权问题漏洞
Vulnerability Description
Documenso是Documenso团队开源的一款数字文档签署平台。 Documenso存在授权问题漏洞,该漏洞源于sign-field-with-token.ts文件对字段类型和所有权验证不足,可能导致具有ASSISTANT角色的接收者获取并完成同一信封中后续未签名接收者的字段,从而伪造其他签名者的签名字段。
CVSS Information
N/A
Vulnerability Type
N/A