Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenSignLabs OpenSign - Information Disclosure
Vulnerability Description
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
OpenSignLabs OpenSign 信息泄露漏洞
Vulnerability Description
OpenSignLabs OpenSign是OpenSignLabs组织的一款数字文档签名解决方案。 OpenSignLabs OpenSign 2.37.0及之前版本存在信息泄露漏洞,该漏洞源于gettenant Parse cloud function接受contactId参数时未进行身份验证或授权检查,可能导致未经身份验证的远程攻击者检索任意组织租户记录,泄露租户配置数据。
CVSS Information
N/A
Vulnerability Type
N/A