QiHang Media Web Digital Signage 3.0.9 Cookie Authentication Credentials Disclosure
Vulnerability Description
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36914
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5578.php
- https://packetstormsecurity.com/files/158858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186770
- https://cxsecurity.com/issue/WLB-2020080059
- https://www.howfor.com/
- https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-cookie-authentication-credentials-disclosure
Affected Vendor
Shenzhen Xingmeng Qihang Media Co., Ltd.
View all reports →