CVE-2020-36924
EUVD-2026-100106.01.2026, 16:15
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sony | bravia_signage | 𝑥 ≤ 1.7.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References