Back to search
CVE-2020-36886
Published: Dec 10, 2025
Modified: Dec 11, 2025
PUBLISHED
Description
SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.
| Vendor | Product | Versions |
|---|---|---|
SpenetiX AG | Fusion Digital Signage | affected 0 - <= 8.2.26 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now