Vulnerabilities
Vulnerable Software
Lg:  >> Supersign Cms  Security Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-06-20
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-06-20
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-06-20
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
CVSS Score
9.8
EPSS Score
0.685
Published
2018-09-21
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
CVSS Score
9.8
EPSS Score
0.026
Published
2018-09-14
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
CVSS Score
8.6
EPSS Score
0.637
Published
2018-09-14
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
CVSS Score
7.5
EPSS Score
0.038
Published
2018-09-14
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-09-14


Contact Us

Shodan ® - All rights reserved