CVE-2020-36883

HIGH

SpinetiX Fusion Digital Signage <3.4.8 - Path Traversal

Title source: llm
STIX 2.1

Description

SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations and delete files by manipulating backup and file delete requests.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/48844

Scores

CVSS v3 8.1
EPSS 0.0063
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
spinetix/fusion_digital_signage < 3.4.8
Published Dec 10, 2025
Tracked Since Feb 18, 2026