iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references. | |
| Title | iDS6 DSSPro Digital Signage System 6.2 Privilege Escalation via Access Control | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-06T19:23:38.829Z
Reserved: 2026-01-03T14:10:13.301Z
Link: CVE-2020-36920
Updated: 2026-01-06T19:12:01.716Z
Status : Received
Published: 2026-01-06T16:15:48.250
Modified: 2026-01-06T20:15:47.677
Link: CVE-2020-36920
No data.
OpenCVE Enrichment
No data.