VYPR

Carousel Digital Signage

by Trms

CVEs (2)

  • CVE-2018-18931HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Services directory, an attacker who has gained access to the system can elevate their privileges from a restricted account to full SYSTEM…

  • CVE-2018-18930HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.03

    The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. An authenticated attacker can upload a crafted ZIP file (based on an…