QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qihang Media
Qihang Media web Digital Signage |
|
| Vendors & Products |
Qihang Media
Qihang Media web Digital Signage |
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions. | |
| Title | QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure | |
| Weaknesses | CWE-530 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T18:52:47.707Z
Reserved: 2025-12-09T11:46:53.452Z
Link: CVE-2020-36899
Updated: 2025-12-11T15:53:13.488Z
Status : Received
Published: 2025-12-10T21:16:02.513
Modified: 2025-12-11T19:15:50.070
Link: CVE-2020-36899
No data.