PT-2025-50516 · Eibiz · Mediaserver

Published

2025-12-10

·

Updated

2025-12-11

·

CVE-2020-36895

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions EIBIZ i-Media Server Digital Signage version 3.8.0
Description The software contains an unauthenticated configuration disclosure issue. Remote attackers can access sensitive configuration files via direct object reference. Specifically, attackers can retrieve the SiteConfig.properties file using an HTTP GET request. This exposure includes administrative credentials, database connection details, and system configuration information.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2020-36895

Affected Products

Mediaserver