CVE-2020-36914
Severity CVSS v4.0:
HIGH
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
06/01/2026
Last modified:
08/01/2026
Description
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2020080059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186770
- https://packetstormsecurity.com/files/158858
- https://www.howfor.com/
- https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-cookie-authentication-credentials-disclosure
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5578.php



