{"id":75619,"date":"2026-01-06T19:22:26","date_gmt":"2026-01-06T15:52:26","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2020-36920-ids6-dsspro-digital-signage-system-6-2-privilege-escalation-via-access-control\/"},"modified":"2026-01-06T19:22:26","modified_gmt":"2026-01-06T15:52:26","slug":"cve-2020-36920-ids6-dsspro-digital-signage-system-6-2-privilege-escalation-via-access-control","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2020-36920-ids6-dsspro-digital-signage-system-6-2-privilege-escalation-via-access-control\/","title":{"rendered":"CVE-2020-36920 &#8211; iDS6 DSSPro Digital Signage System 6.2 Privilege Escalation via Access Control"},"content":{"rendered":"<p>CVE ID : CVE-2020-36920<\/p>\n<p>Published :  Jan. 6, 2026, 3:52 p.m. | 34\u00a0minutes ago<\/p>\n<p>Description : iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.<\/p>\n<p>Severity: 8.8 | HIGH<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2020-36920 Published : Jan. 6, 2026, 3:52 p.m. | 34\u00a0minutes ago Description : iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-75619","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/75619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=75619"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/75619\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=75619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=75619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=75619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}