Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36924. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote file inclusion (RFI) vulnerability in Sony BRAVIA Digital Signage 1.7.8. It allows arbitrary client-side script inclusion via a crafted POST request to the content-creation API endpoint.
Description
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.
Exploits (1)
This exploit demonstrates an unauthenticated remote file inclusion (RFI) vulnerability in Sony BRAVIA Digital Signage 1.7.8. It allows arbitrary client-side script inclusion via a crafted POST request to the content-creation API endpoint.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N