vendor:
BRAVIA Digital Signage
by:
LiquidWorm
8.8
CVSS
HIGH
Unauthenticated Remote File Inclusion
98
CWE
Product Name: BRAVIA Digital Signage
Affected Version From: <=1.7.8
Affected Version To: <=1.7.8
Patch Exists: NO
Related CWE: N/A
CPE: a:sony:bravia_digital_signage:1.7.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows Server 2012 R2, Ubuntu, NodeJS, Express
2020
Sony BRAVIA Digital Signage 1.7.8 – Unauthenticated Remote File Inclusion
Sony's BRAVIA Signage is an application to deliver video and still images to Pro BRAVIAs and manage the information via a network. BRAVIA digital signage is vulnerable to a remote file inclusion (RFI) vulnerability by including arbitrary client-side dynamic scripts (JavaScript, VBScript, HTML) when adding content though the input URL material of type html. This allows hijacking the current session of the user, execute cross-site scripting code or changing the look of the page and content modification on current display.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.