PT-2026-1447 · All Dynamics · Enlogic:Show Digital Signage System

Published

2026-01-06

·

Updated

2026-01-06

·

CVE-2020-36913

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions All-Dynamics Software enlogic:show version 2.0.2
Description An issue exists where attackers can set a predefined PHP session identifier during the login process. By forging HTTP GET requests to the endpoint 'welcome.php' using a manipulated session token, authentication can be bypassed, potentially leading to cross-site request forgery attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2020-36913

Affected Products

Enlogic:Show Digital Signage System