Description

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.

INFO

Published Date :

2025-12-10T20:55:02.794Z

Last Modified :

2025-12-11T18:53:06.885Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2020-36896 vulnerability.

Vendors Products
Qihang Media
  • Web Digital Signage

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability