Cross-Site Request Forgery Vulnerability in SpinetiX Fusion Digital Signage
CVE-2020-36886
Key Information:
- Vendor
Spenetix Ag
- Status
- Vendor
- CVE Published:
- 10 December 2025
Badges
What is CVE-2020-36886?
The SpinetiX Fusion Digital Signage version 3.4.8 has a vulnerability that allows malicious actors to exploit cross-site request forgery (CSRF) attacks. By enticing logged-in users to visit a crafted web page, an attacker can automatically create an administrative account without proper request validation. This poses a significant risk as it grants unauthorized users full system privileges, potentially leading to further security breaches.
Affected Version(s)
Fusion Digital Signage 0 <= 8.2.26
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
