CVE-2020-36899

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:howfor:qihang_media_web_digital_signage:3.0.9:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-10 21:16

Updated : 2025-12-17 19:01


NVD link : CVE-2020-36899

Mitre link : CVE-2020-36899

CVE.ORG link : CVE-2020-36899


JSON object : View

Products Affected

howfor

  • qihang_media_web_digital_signage
CWE
CWE-530

Exposure of Backup File to an Unauthorized Control Sphere