{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2020-36912", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-01-03T14:10:13.301Z", "datePublished": "2026-01-06T15:52:23.088Z", "dateUpdated": "2026-01-06T19:29:31.634Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-01-06T15:52:23.088Z" }, "datePublic": "2020-07-19T00:00:00.000Z", "title": "Plexus anblick Digital Signage Management 3.1.13 Open Redirect via Pagina Parameter", "descriptions": [ { "lang": "en", "value": "Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "URL Redirection to Untrusted Site ('Open Redirect')", "cweId": "CWE-601", "type": "CWE" } ] } ], "affected": [ { "vendor": "Plexus", "product": "Plexus anblick Digital Signage Management", "versions": [ { "version": "3.1.13", "status": "affected" } ] } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 5.1, "baseSeverity": "MEDIUM", "exploitMaturity": "NOT_DEFINED", "privilegesRequired": "NONE", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "LOW", "userInteraction": "ACTIVE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "LOW", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS" }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS" } ], "references": [ { "url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5573.php", "name": "Zero Science Lab Disclosure (ZSL-2020-5573)", "tags": [ "third-party-advisory" ] }, { "url": "https://packetstormsecurity.com/files/158473", "name": "Packet Storm Security Exploit Entry", "tags": [ "exploit" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/185521", "name": "IBM X-Force Vulnerability Exchange Entry", "tags": [ "vdb-entry" ] }, { "url": "https://www.plexus.es/", "name": "Plexus Vendor Homepage", "tags": [ "product" ] }, { "name": "VulnCheck Advisory: Plexus anblick Digital Signage Management 3.1.13 Open Redirect via Pagina Parameter", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/plexus-anblick-digital-signage-management-open-redirect-via-pagina-parameter" } ], "credits": [ { "lang": "en", "value": "LiquidWorm as Gjoko Krstic of Zero Science Lab", "type": "finder" } ], "x_generator": { "engine": "vulncheck" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-01-06T19:28:26.807693Z", "id": "CVE-2020-36912", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-01-06T19:29:31.634Z" } } ] } }