VYPR
Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Dec 11, 2025

UBICOD Medivision Digital Signage 1.5.1 Cross-Site Request Forgery via User Management

CVE-2020-36901

Description

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Range: = 1.5.1
  • UBICOD Co., Ltd. | MEDIVISION INC./UBICOD Medivision Digital Signagev5
    Range: Firmware 1.5.1 (2013.01.3)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.