Supersign Cms
Vendor:
First CVE: Sep 14, 2018 · Active for 7 years
8
Total CVEs
More Total CVEs than 87% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Supersign Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2018
7 years ago
Most Recent CVE
Jun 20, 2024
768 days ago
CVE Severity & Scoring
Supersign Cms8 CVEs
38%
25%
38%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17173CRITICAL LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Sep 21, 2018 | 9.8 | 81 | NO | YES |
CVE-2018-16288HIGH LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. | Sep 14, 2018 | 8.6 | 65 | NO | YES |
CVE-2018-16286CRITICAL LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits. | Sep 14, 2018 | 9.8 | 41 | NO | NO |
CVE-2018-16287CRITICAL LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. | Sep 14, 2018 | 9.8 | 40 | NO | NO |
CVE-2018-16706HIGH LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080. | Sep 14, 2018 | 7.5 | 35 | NO | NO |
CVE-2024-6179MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSig | Jun 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-6178MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSig | Jun 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-6177MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects S | Jun 20, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
25.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
25.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Supersign Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5 | 2 | 9.2 | 46.0% | 0 | 2 |