EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eibiz
Eibiz i-media Server Digital Signage |
|
| Vendors & Products |
Eibiz
Eibiz i-media Server Digital Signage |
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information. | |
| Title | EIBIZ i-Media Server Digital Signage 3.8.0 Unauthenticated Configuration Disclosure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T18:53:13.202Z
Reserved: 2025-12-09T11:46:53.451Z
Link: CVE-2020-36895
Updated: 2025-12-11T15:56:36.482Z
Status : Received
Published: 2025-12-10T21:16:01.900
Modified: 2025-12-11T19:15:49.563
Link: CVE-2020-36895
No data.