CVE-2020-36918: Yerootech IDS6 Dsspro Digital Signage System

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF protections.

Affected products

  • Yerootech IDS6 Dsspro Digital Signage System: version 6.2 B2014.12.12.1220 only; version 5.6 B2017.07.12.1757 only; version 4.3 only

Published 2026-01-06. Last modified 2026-06-17.