Vulnerability Details CVE-2020-36901
UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2020-36901
-
cpe:2.3:h:medivision:medivision_digital_signage:-
-
cpe:2.3:o:medivision:medivision_digital_signage_firmware:1.5.1