Supersign Cms

Vendor:

First CVE: Sep 14, 2018 · Active for 7 years

8
Total CVEs
More Total CVEs than 87% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Supersign Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2018
7 years ago
Most Recent CVE
Jun 20, 2024
768 days ago

CVE Severity & Scoring

Supersign Cms8 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
Sep 21, 20189.881NOYES
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
Sep 14, 20188.665NOYES
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
Sep 14, 20189.841NONO
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
Sep 14, 20189.840NONO
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
Sep 14, 20187.535NONO
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSig
Jun 20, 20246.118NONO
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSig
Jun 20, 20246.118NONO
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects S
Jun 20, 20246.118NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
25.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
25.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Supersign Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.529.246.0%02