CVE-2020-36892
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-17
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eibiz | i-media_server_digital_signage | 3.8.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Eibiz i-Media Server Digital Signage 3.8.0 and allows attackers to escalate privileges without authentication by exploiting the updateUser object via the /messagebroker/amf endpoint. Attackers can modify user roles and take over user accounts by manipulating role settings without needing to log in.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized privilege escalation, allowing attackers to gain control over user accounts and potentially take over the system. This can result in unauthorized access, data manipulation, and compromise of the affected server.