ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36900”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36900
Published
2025-12-10
CVSS:
8.6
ShadowTrackr CVSS:
6.1
Summary:
All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when a logged-in user visits the page.