CVE-2020-36917

Severity CVSS v4.0:
HIGH
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
06/01/2026
Last modified:
06/01/2026

Description

iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.