PT-2025-50520 · Qihang · Qihang Media Web Digital Signage

Published

2025-12-10

·

Updated

2025-12-11

·

CVE-2020-36899

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions QiHang Media Web Digital Signage version 3.0.9
Description The software contains an unauthenticated file disclosure issue that allows remote attackers to access sensitive files. This is possible through the manipulation of filename and path parameters without authentication. Attackers can exploit the 'QH.aspx' API endpoint by using the download and getAll actions to read arbitrary files and directory contents.
Recommendations Apply any available updates to address the issue. As a temporary workaround, restrict access to the 'QH.aspx' endpoint. Avoid using the filename and path parameters in the 'QH.aspx' endpoint until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-36899

Affected Products

Qihang Media Web Digital Signage