QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
References
| Link | Resource |
|---|---|
| http://www.howfor.com | Product |
| https://www.exploit-db.com/exploits/48750 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-arbitrary-file-disclosure | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/48750 | Exploit Third Party Advisory VDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php | Exploit Third Party Advisory |
Configurations
History
17 Dec 2025, 19:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.howfor.com - Product | |
| References | () https://www.exploit-db.com/exploits/48750 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-arbitrary-file-disclosure - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php - Exploit, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:howfor:qihang_media_web_digital_signage:3.0.9:*:*:*:*:*:*:* | |
| First Time |
Howfor
Howfor qihang Media Web Digital Signage |
11 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/48750 - | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php - |
10 Dec 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-10 21:16
Updated : 2025-12-17 19:01
NVD link : CVE-2020-36899
Mitre link : CVE-2020-36899
CVE.ORG link : CVE-2020-36899
JSON object : View
Products Affected
howfor
- qihang_media_web_digital_signage
CWE
CWE-530
Exposure of Backup File to an Unauthorized Control Sphere
