CNNVD-202512-1810 Information

CNNVD ID

CNNVD-202512-1810

CVE-2020-36896

  • CNNVD Published: 2025-12-10

Description (Chinese)

QiHang Media Web Digital Signage是中国QiHang公司的一个数字标牌管理软件。 QiHang Media Web Digital Signage 3.0.9版本存在安全漏洞,该漏洞源于未保护的XML文件存在明文凭据,可能导致认证绕过。

Description (English)

QiHang Media Web Digital Signage is a digital brand management software for QiHang in China. QiHang Media Web Digital Signage, version 3.0.9, contains a security loophole, which stems from the existence of explicit diplomas in unprotected XML documents, which may result in the certification being bypassed.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

QiHang

Published

2025-12-10

Last Modified

2026-02-24

References

http://www.howfor.com https://www.exploit-db.com/exploits/48748 https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-cleartext-credentials-disclosure https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5579.php

Share on: