CVE-2020-36896 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login infor…
High CVSS: 8.7

CVE-2020-36896

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.
Vendor
Howfor
Product
Qihang Media Web Digital Signage
CWE
CWE-522
Yayın Tarihi
2025-12-10 21:16:02
Güncelleme
2025-12-17 19:21:26
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar