VYPR

Digital Signage System

by iDS6 DSSPro

CVEs (2)

  • CVE-2020-36917HigJan 6, 2026
    risk 0.49cvss 7.5epss 0.00

    iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.

  • CVE-2020-36900Dec 10, 2025
    risk 0.00cvss epss 0.00

    All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when a logged-in user visits the page.