Back to search
CVE-2020-36901
Published: Dec 10, 2025
Modified: Dec 11, 2025
PUBLISHED
Description
UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.
| Vendor | Product | Versions |
|---|---|---|
UBICOD Co., Ltd. | MEDIVISION INC. | UBICOD Medivision Digital Signage | affected Firmware 1.5.1 (2013.01.3) |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now