{"id":"CVE-2024-52270","title":"PDF Document Spoofing in DropBox Sign(HelloSign)","summary":"User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing.\nDisplayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrom…","severity":"high","cvss":8.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/AU:Y/U:Red","cvssSource":"cna","cwe":["CWE-451"],"vendor":"DropBox(HelloSign)","product":"DropBox Sign","affected":["dropbox_sign <= 2024-12-04"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2024-12-05T14:49:19.543227Z"},"exploitAvailable":true,"published":"2024-12-05","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:45:33.592Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2024-52270","references":[{"url":"https://www.vulsec.org/advisories"},{"url":"https://www.loom.com/share/48f63594e14c49e19840ad9cb7d60453?sid=816c6afa-0b67-4b0b-98ff-d5c58d464038"},{"url":"https://new.space/s/ZuHoujvkjdzfY7Uihah7Yg#SKWLU_g2Cihfj4qsq9XNy6F4saxVAzD876PujiDOYfs"},{"url":"https://drive.proton.me/urls/Z6DHXNRZQC#jkfO38rjOiOj"},{"url":"https://sign.dropbox.com/"},{"url":"https://app.hellosign.com/"}],"tags":["cve.org","exploit-available"],"epss":0.00193,"epssPercentile":0.09239,"ingestedAt":"2026-09-21T18:50:57.575Z","slug":"CVE-2024-52270","body":"## Overview\n\nUser Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing.\nDisplayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.\nThis issue affects DropBox Sign(HelloSign): through 2024-12-04.\n\n## Affected\n\n- `dropbox_sign <= 2024-12-04`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\n* If other party initiated e-signing - Download the PDF file for a security professionals/educated persons inspection\n*  If possible - Download the PDF file and perform full flattening (of the entire document, not just form fields)","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}