PT-2025-50510 · Spinetix · Spinetix Fusion

CVE-2020-36886

·

Published

2025-12-10

·

Updated

2025-12-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SpinetiX Fusion Digital Signage version 3.4.8
Description The software contains a cross-site request forgery issue that allows attackers to create administrative user accounts without proper request validation. An attacker can create a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.
Recommendations Apply updates to address the improper request validation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36886

Affected Products

Spinetix Fusion