Skip to main content

Vendor/product archive

lg / supersign_cms CVEs

Beta · best-effort

8 CVEs tagged to lg / supersign_cms3 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-6179

Published Jun 20, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6178

Published Jun 20, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6177

Published Jun 20, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17173

Published Sep 21, 2018

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2018-16706

Published Sep 14, 2018

LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16288

Published Sep 14, 2018

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16287

Published Sep 14, 2018

LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16286

Published Sep 14, 2018

LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1