Yerootech iDS6 DSSPro Digital Signage System Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Yerootech iDS6 DSSPro Digital Signage System version 6.2. This vulnerability allows authenticated users to bypass access controls and elevate privileges by using console JavaScript functions or exploiting insecure direct object references. As a result, attackers could create users, modify roles and permissions, and potentially take over the entire application.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing users to gain elevated rights within the application and potentially take full control of the system.

Reproduction

To reproduce this vulnerability, log into the application using one of the default accounts (admin:123456, boss:boss, or user:user). Once logged in, navigate to the Accounts>User page. From there, JavaScript functions can be called in the console to exploit the access control vulnerability. Alternatively, insecure direct object references can be used to access hidden functionalities that allow for privilege escalation.

Added: Jan 6, 2026, 4:34 PM
Updated: Jan 6, 2026, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.