CVE-2020-36899

Q

iHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

Configurations

Configuration 1 (hide)

cpe:2.3:a:howfor:qihang_media_web_digital_signage:3.0.9:*:*:*:*:*:*:*

History

17 Dec 2025, 19:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 21:16

Updated : 2025-12-17 19:01


NVD link : CVE-2020-36899

Mitre link : CVE-2020-36899

CVE.ORG link : CVE-2020-36899


JSON object : View

CWE
CWE-530

Exposure of Backup File to an Unauthorized Control Sphere