Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
References
Configurations
No configuration.
History
06 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php - |
06 Jan 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-06 16:15
Updated : 2026-01-06 19:15
NVD link : CVE-2020-36923
Mitre link : CVE-2020-36923
CVE.ORG link : CVE-2020-36923
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
