ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36896”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36896
Published
2025-12-10
CVSS:
8.7
ShadowTrackr CVSS:
6.6
Summary:
QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.