Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Medivision medivision Digital Signage
Medivision medivision Digital Signage Firmware |
|
| CPEs | cpe:2.3:h:medivision:medivision_digital_signage:-:*:*:*:*:*:*:* cpe:2.3:o:medivision:medivision_digital_signage_firmware:1.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Medivision medivision Digital Signage
Medivision medivision Digital Signage Firmware |
|
| Metrics |
cvssV3_1
|
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Medivision
Medivision digital Signage |
|
| Vendors & Products |
Medivision
Medivision digital Signage |
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges. | |
| Title | UBICOD Medivision Digital Signage 1.5.1 Cross-Site Request Forgery via User Management | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T18:52:35.866Z
Reserved: 2025-12-09T11:46:53.452Z
Link: CVE-2020-36901
Updated: 2025-12-11T15:52:40.723Z
Status : Analyzed
Published: 2025-12-10T21:16:02.847
Modified: 2025-12-30T20:30:12.703
Link: CVE-2020-36901
No data.
OpenCVE Enrichment
Updated: 2025-12-11T21:37:57Z