← Advisories

iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass

Low
Advisory ID
ZSL-2020-5607
Release Date
04 November 2020
Vendor
Guangzhou Yeroo Tech Co., Ltd. - http://www.yerootech.com
Affected Version
V6.2 B2014.12.12.1220, V5.6 B2017.07.12.1757, V4.3
CVE
N/A
Tested On
Microsoft Windows XP, Microsoft Windows 7, Microsfot Windows Server 2008, Microsoft Windows Server 2012, Microsoft Windows 10, Apache Tomcat/8.0.44, Apache Tomcat/6.0.35, Apache-Coyote/1.1, Apache Axis/1.4, MySQL 5.5.25, Java 1.8.0
Summary

iDS6 Software's DSSPro network digital signage management system is a web-based server software solution for Windows.

Description

The CAPTCHA function for DSSPro is prone to a security bypass vulnerability that occurs in the CAPTCHA authentication routine. By requesting the autoLoginVerifyCode object an attacker can receive a JSON message code and successfully bypass the CAPTCHA-based authentication challenge and perform brute-force attacks.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
04.11.2020Initial release
11.11.2020Added reference [1], [2], [3] and [4]