📦

supersign_cms

Vendor: lg

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 2 Remote Access
Total CVEs 8 Total Indexed
Avg. EPSS 18.23% Exploit Prob.
Latest CVE CVE-2024-6179 Jun 20

Security Vulnerability Index

Page 1 / 1
4.8 CVSS

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

EPSS: 0.66%
4.8 CVSS

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

EPSS: 0.66%
4.8 CVSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

EPSS: 0.66%
9.8 CVSS
CVE-2018-17173
RCE Exploit Found

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

EPSS: 79.03%
7.5 CVSS
CVE-2018-16706
Exploit Found

LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

EPSS: 0.51%
8.6 CVSS
CVE-2018-16288
Exploit Found

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

EPSS: 62.70%
9.8 CVSS

LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

EPSS: 0.57%
9.8 CVSS

LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.

EPSS: 1.01%