← Back

Supersign Cms

supersign_cms

Vendor: Lg • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lg
1Supersign Cms
Nov 21, 2024
Jun 20, 2024
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
1Lg
1Supersign Cms
Nov 21, 2024
Jun 20, 2024
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
1Lg
1Supersign Cms
Nov 21, 2024
Jun 20, 2024
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.