VYPR
Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Dec 11, 2025

SpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup Disclosure

CVE-2020-36887

Description

SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.