What is CVE-2026-72545?
An IDOR (Insecure Direct Object Reference) vulnerability in OpenSignLabs OpenSign through version 2.37.0 allows unauthenticated remote attackers to write to any contact record using the 'updatecontacttour' Parse cloud function. The function lacks both authentication and authorization checks before modifying the targeted contact. Users are advised to upgrade to the latest version and enforce authentication for the vulnerable function.
Azərbaycanca: OpenSignLabs OpenSign-in 2.37.0 və daha əvvəlki versiyalarında IDOR (Insecure Direct Object Reference) zəifliyi aşkar edilib. Bu boşluq autentifikasiya olunmamış uzaq hücumçulara 'updatecontacttour' Parse bulud funksiyası vasitəsilə istənilən kontakt qeydinə yazmağa imkan verir. Mütəxəssislər proqramı ən son versiyaya yeniləməyi və funksiya üçün autentifikasiya mexanizmlərini məcburi etməyi tövsiyə edir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: OpenSignLabs
FAQ2
What type of vulnerability was found in the 'updatecontacttour' Parse cloud function of OpenSignLabs OpenSign?
An IDOR (Insecure Direct Object Reference) vulnerability was found that allows unauthenticated remote attackers to write to any contact record.
Is authentication required for an attacker to exploit this vulnerability?
No, the vulnerability allows unauthenticated attackers to write to contact records via the 'updatecontacttour' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.