Eibiz i-Media Server Digital Signage Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Eibiz i-Media Server Digital Signage version 3.8.0. This vulnerability allows unauthenticated attackers to modify user roles through the updateUser object, effectively elevating privileges and taking over user accounts. The /messagebroker/amf endpoint is exploited to manipulate role settings without authentication.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation and account takeover by modifying user roles.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the /messagebroker/amf endpoint. This request must include the updateUser object, which is part of the ActionScript object graphs. The payload should be serialized in a specific format that includes the target username, password, display name, and the desired role (such as 'Administrator'). Once the request is sent, the user account will be updated with the new role, effectively escalating privileges or taking over the account.

Added: Dec 10, 2025, 9:49 PM
Updated: Dec 10, 2025, 9:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.