UBICOD Medivision Digital Signage Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in UBICOD Medivision Digital Signage version 1.5.1. This vulnerability allows attackers to create administrative user accounts without proper request validation. By crafting a malicious web page that submits a form to the '/query/user/itSet' endpoint, attackers can add new admin users with elevated privileges.

Impact

Exploitation of this vulnerability allows for the creation of administrative user accounts, potentially leading to unauthorized access and privileges within the application.

Reproduction

To reproduce this vulnerability, a logged-in user must be tricked into visiting a malicious web page that submits a crafted form to the '/query/user/itSet' endpoint. The form must include the necessary data to create a new admin user, such as username, password, email, mobile number, phone number, approval status, and group ID.

Added: Dec 10, 2025, 9:34 PM
Updated: Dec 10, 2025, 9:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.