Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83pw-28qw-xg2h

Опубликовано: 06 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.5

Описание

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

EPSS

Процентиль: 17%
0.00054
Низкий

8.6 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

EPSS

Процентиль: 17%
0.00054
Низкий

8.6 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-319