CVE-2020-36899
HIGHDescription
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| howfor | qihang_media_web_digital_signage |
References
Exploits
Frequently Asked Questions
What is CVE-2020-36899? +
How severe is CVE-2020-36899? +
What products are affected by CVE-2020-36899? +
How do I check if I'm vulnerable to CVE-2020-36899? +
Related Vulnerabilities
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to …
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive …
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to …
A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an …
A vulnerability classified as problematic has been found in fridgecow smartalarm 1.8.1 on Android. This affects an unknown part of …
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Replify-Messenger 1.0 on Android. …