CNNVD-202601-1025 Information

CNNVD ID

CNNVD-202601-1025

CVE-2020-36918

  • CNNVD Published: 2026-01-06

Description (Chinese)

Phoenix Contact iDS6 DSSPro是美国iDS6公司的一款数字标牌管理系统。 Phoenix Contact iDS6 DSSPro 6.2版本存在安全漏洞,该漏洞源于容易受到跨站请求伪造攻击,可能导致添加未经授权的用户。

Description (English)

Phoenix Contact iDS6 DSSPro is a digital tag management system for iDS6 in the United States. Version 6.2 of Phoenix Contact iDS6 DSSPro contains a security loophole that stems from its vulnerability to cross-site requests for fraudulent attacks and may lead to the addition of unauthorized users.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

iDS6

Published

2026-01-06

Last Modified

2026-02-24

References

https://cxsecurity.com/issue/WLB-2020110022 https://exchange.xforce.ibmcloud.com/vulnerabilities/191258 https://packetstormsecurity.com/files/159916 http://www.yerootech.com/ https://web.archive.org/web/20200919100215/ https://www.exploit-db.com/exploits/48990 https://www.vulncheck.com/advisories/ids-dsspro-digital-signage-system-cross-site-request-forgery-via-user-management https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5606.php

Share on: