CVE-2020-36920
Last modified
CVE-2020-36920 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2020-36920?
How severe is CVE-2020-36920?
How do I fix CVE-2020-36920?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36915Adtec Digital SignEdje Digital Signage Player v2.08.28 conta…8.7
- CVE-2020-36916TDM Digital Signage PC Player 4.1.0.4 contains an elevation …8.8
- CVE-2020-36917iDS6 DSSPro Digital Signage System 6.2 contains a sensitive …8.6
- CVE-2020-36918iDS6 DSSPro Digital Signage System 6.2 contains a cross-site…5.1
- CVE-2020-36919WPForms 1.7.8 contains a cross-site scripting vulnerability …6.1
- CVE-2020-3692u'Possible buffer overflow while updating output buffer for …9.8
- CVE-2020-36921RED-V Super Digital Signage System 5.1.1 contains an informa…7.5
- CVE-2020-36922Sony BRAVIA Digital Signage 1.7.8 contains an information di…7.5
- CVE-2020-36923Sony BRAVIA Digital Signage 1.7.8 contains an insecure direc…9.8
- CVE-2020-36924Sony BRAVIA Digital Signage 1.7.8 contains a remote file inc…6.1
- CVE-2020-36925Arteco Web Client DVR/NVR contains a session hijacking vulne…9.8
- CVE-2020-36926SmarterTrack 7922 contains an information disclosure vulnera…5.3
Are you affected by CVE-2020-36920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
