Executive brief
OpenSign is an open-source document signing platform that serves as an alternative to DocuSign. A vulnerability allows attackers to modify any user's contact information without authentication, potentially corrupting data, impersonating users, or disrupting service for all users in the system.
Technical details
An insecure direct object reference (IDOR) vulnerability exists in the updatecontacttour Parse cloud function in OpenSign through version 2.37.0. The function fails to perform authentication or authorization checks before updating contact records, allowing unauthenticated remote attackers to modify any contact record by directly specifying the target object ID. An attacker can corrupt, overwrite, or delete contact data for arbitrary users without requiring credentials or valid authentication tokens, potentially enabling account hijacking or data manipulation attacks.
Affected products
- OpenSignLabs OpenSign through 2.37.0
Timeline
- 2026-08-11: disclosed