iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.
History

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.
Title iDS6 DSSPro Digital Signage System 6.2 Privilege Escalation via Access Control
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-06T19:23:38.829Z

Reserved: 2026-01-03T14:10:13.301Z

Link: CVE-2020-36920

cve-icon Vulnrichment

Updated: 2026-01-06T19:12:01.716Z

cve-icon NVD

Status : Received

Published: 2026-01-06T16:15:48.250

Modified: 2026-01-06T20:15:47.677

Link: CVE-2020-36920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.