Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials. | |
| Title | OpenSignLabs OpenSign - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:07:50.383Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72545
Updated: 2026-08-11T15:07:42.768Z
Status : Received
Published: 2026-08-11T12:17:39.987
Modified: 2026-08-11T16:17:34.817
Link: CVE-2026-72545
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:15:06Z