Description
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.
Problem types
CWE-451 User Interface (UI) Misrepresentation of Critical Information
Product status
Any version
Credits
Erez Kalman
References
www.vulsec.org/advisories
www.loom.com/...453?sid=816c6afa-0b67-4b0b-98ff-d5c58d464038
new.space/s/ZuHoujvkjdzfY7Uihah7Yg
drive.proton.me/urls/Z6DHXNRZQC
sign.dropbox.com/
app.hellosign.com/