CVE-2020-36892
CRITICALEibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36892. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit targets Eibiz i-Media Server Digital Signage 3.8.0, leveraging an unauthenticated privilege escalation vulnerability via AMF deserialization to elevate a user's role to Administrator or take over an existing account.
Description
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate privileges and take over user accounts by manipulating role settings without authentication.
Exploits (1)
This exploit targets Eibiz i-Media Server Digital Signage 3.8.0, leveraging an unauthenticated privilege escalation vulnerability via AMF deserialization to elevate a user's role to Administrator or take over an existing account.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H