CVE-2020-36905
Unknown
Unknown - Not Provided
Remote File Inclusion in FIBARO Home Center 5 Enables Session Hijack
Publication date: 2026-01-06
Last updated on: 2026-01-06
Assigner: VulnCheck
Description
Description
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fibar_group_s.a. | fibar_system_home_center | to 5.021.38 (inc) |
| fibar_group_s.a. | fibar_system_home_center | 4.580 |
| fibar_group_s.a. | fibar_system_home_center | 4.570 |
| fibar_group_s.a. | fibar_system_home_center | 4.540 |
| fibar_group_s.a. | fibar_system_home_center | 4.530 |
| fibar_group_s.a. | fibar_system_home_center | 4.510 |
| fibar_group_s.a. | fibar_system_home_center | 4.180 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-829 | The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. |