Home / os / win10

Sony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File Inclusion

Posted on 03 December 2020

Sony BRAVIA Digital Signage versions 1.7.8 and below are vulnerable to a remote file inclusion vulnerability by including arbitrary client-side dynamic scripts (JavaScript, VBScript, HTML) when adding content though the input URL material of type html. This allows hijacking of the current session of the user, execute cross-site scripting code, or changing the look of the page and content modification on current display.

 

TOP