Lucene search

K

Supersign Cms Security Vulnerabilities

cve
cve

CVE-2018-16286

LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.

9.8CVSS

9.5AI Score

0.007EPSS

2018-09-14 09:29 PM
20
cve
cve

CVE-2018-16287

LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

9.8CVSS

9.4AI Score

0.006EPSS

2018-09-14 09:29 PM
33
cve
cve

CVE-2018-16288

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

8.6CVSS

8.5AI Score

0.104EPSS

2018-09-14 09:29 PM
44
cve
cve

CVE-2018-16706

LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

7.5CVSS

7.5AI Score

0.001EPSS

2018-09-14 09:29 PM
29
cve
cve

CVE-2018-17173

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

9.8CVSS

9.7AI Score

0.871EPSS

2018-09-21 05:29 PM
81
cve
cve

CVE-2023-40517

LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vul...

7.5CVSS

7.1AI Score

0.001EPSS

2024-05-03 03:15 AM
29
cve
cve

CVE-2023-41181

LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The...

5.3CVSS

4.9AI Score

0.001EPSS

2024-05-03 03:15 AM
30
cve
cve

CVE-2024-6177

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

6.1CVSS

6.5AI Score

0.0005EPSS

2024-06-20 02:15 AM
26
cve
cve

CVE-2024-6178

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

6.1CVSS

6.5AI Score

0.0005EPSS

2024-06-20 02:15 AM
26
cve
cve

CVE-2024-6179

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

6.1CVSS

6.5AI Score

0.0005EPSS

2024-06-20 02:15 AM
29