PT-2026-1451 · Guangzhou Yeroo Tech Co. · Ids6 Dsspro Digital Signage System

Published

2026-01-06

·

Updated

2026-01-06

·

CVE-2020-36917

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iDS6 DSSPro Digital Signage System version 6.2
Description An information disclosure issue allows remote attackers to intercept authentication credentials because cookies are transmitted in cleartext. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2020-36917

Affected Products

Ids6 Dsspro Digital Signage System