VYPR
Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Dec 11, 2025

UBICOD Medivision Digital Signage 1.5.1 Cross-Site Request Forgery via User Management

CVE-2020-36901

Description

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.

Affected products

2
  • Range: = 1.5.1
  • UBICOD Co., Ltd. | MEDIVISION INC./UBICOD Medivision Digital Signagev5
    Range: Firmware 1.5.1 (2013.01.3)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.