Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials. | |
| Title | OpenSignLabs OpenSign - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:07:50.383Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72545
Updated: 2026-08-11T15:07:42.768Z
Status : Received
Published: 2026-08-11T12:17:39.987
Modified: 2026-08-11T16:17:34.817
Link: CVE-2026-72545
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:15:06Z