CVE-2024-52271
User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.
This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
- Base score: 8.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.21%
- Percentile among all scored CVEs: 10
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1203Exploitation for Client Executionexecution85 % - Primary impact
T1565.001Stored Data Manipulationimpact75 % - Secondary impact
T1566.002Spearphishing Linkinitial access60 %
UI misrepresentation requiere interacción del usuario (UI:P) con documento preparado → T1203. Impacto: manipulación de datos mostrados (capas no aplanadas en impresión) → T1565.001; potencial para phishing con adjunto falsificado → T1566.002.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-451
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-52271",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-52271",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-12-05T14:14:26.736144Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.2,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "RED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe",
"affectedData": [
{
"repo": "https://github.com/documenso/documenso",
"vendor": "Documenso",
"product": "Documenso",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "git",
"lessThanOrEqual": "1.8.0"
},
{
"status": "affected",
"version": ">1.8.0",
"versionType": "git"
}
],
"defaultStatus": "affected"
},
{
"vendor": "Documenso",
"product": "Documenso SaaS (Hosted)",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "date",
"lessThanOrEqual": "2024-12-05"
},
{
"status": "affected",
"version": "2024-12-05",
"versionType": "date"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:documenso:documenso:*:*:*:*:*:*:*:*"
],
"vendor": "documenso",
"product": "documenso",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "git",
"lessThanOrEqual": "1.8.0"
},
{
"status": "affected",
"version": "1.8.0*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:documenso:documenso:*:*:*:*:saas:*:*:*"
],
"vendor": "documenso",
"product": "documenso",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2024-12-05"
},
{
"status": "affected",
"version": "2024-12-05"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-12-05T14:15:21.417",
"references": [
{
"url": "https://github.com/documenso/documenso",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe"
},
{
"url": "https://github.com/documenso/documenso/issues/1512",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe"
},
{
"url": "https://www.documenso.com/",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe"
},
{
"url": "https://www.vulsec.org/advisories",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe",
"description": [
{
"lang": "en",
"value": "CWE-451"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.\n\n\nThis issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05."
},
{
"lang": "es",
"value": "La vulnerabilidad de tergiversación de información crítica en la interfaz de usuario (IU) de Documenso permite la suplantación de contenido. La versión mostrada no muestra la versión aplanada de capas una vez descargada. Si se imprime (por ejemplo, a través de Google Chrome -> Examinar la vista previa de impresión): solo se mostrará la vulnerabilidad, no se aplanarán todas las capas. Este problema afecta a Documenso: hasta 1.8.0, >1.8.0 y Documenso SaaS (alojado) a partir del 5 de diciembre de 2024."
}
],
"lastModified": "2026-06-17T08:06:54.807",
"sourceIdentifier": "2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe"
}