Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fqg-hhc5-9x33

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

EPSS

Процентиль: 70%
0.00642
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-530

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

EPSS

Процентиль: 70%
0.00642
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-530