CVE-2024-52270
Published: 05 December 2024
Summary
CVE-2024-52270 is a high-severity User Interface (UI) Misrepresentation of Critical Information (CWE-451) vulnerability. Its CVSS base score is 8.2 (High).
Operationally, ranked at the 23.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-46111
Vulnerability details
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability…
more
only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.