Vulnerability Description
All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when a logged-in user visits the page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| All-Dynamics | Digital Signage System | 2.0.2 |
Related Weaknesses (CWE)
References
- https://www.all-dynamics.deProduct
- https://www.exploit-db.com/exploits/48736ExploitThird Party Advisory
- https://www.vulncheck.com/advisories/all-dynamics-digital-signage-system-cross-sThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5576.phpThird Party AdvisoryExploit
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5576.phpThird Party AdvisoryExploit
FAQ
What is CVE-2020-36900?
CVE-2020-36900 is a vulnerability with a CVSS score of 8.8 (HIGH). All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craf...
How severe is CVE-2020-36900?
CVE-2020-36900 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36900?
Check the references section above for vendor advisories and patch information. Affected products include: All-Dynamics Digital Signage System.