CNNVD-202512-1809 Information

CNNVD ID

CNNVD-202512-1809

CVE-2020-36898

  • CNNVD Published: 2025-12-10

Description (Chinese)

QiHang Media Web Digital Signage是中国QiHang公司的一个数字标牌管理软件。 QiHang Media Web Digital Signage 3.0.9版本存在路径遍历漏洞,该漏洞源于QH.aspx端点存在文件删除,可能导致任意文件删除。

Description (English)

QiHang Media Web Digital Signage is a digital brand management software for QiHang in China. Version 3.0.9 of QiHang Media Web Digital Signage has a loophole in its path, which stems from the deletion of the QH.aspx endpoint, which may lead to the deletion of any file.

Hazard Level

High

Vulnerability Type

路径遍历

Affected Vendor

QiHang

Published

2025-12-10

Last Modified

2026-02-24

References

http://www.howfor.com https://www.exploit-db.com/exploits/48749 https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-arbitrary-file-deletion https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5580.php

Share on: