CVE-2020-36914
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-319
Transmisión de información sensible en texto claro
Fecha de publicación:
06/01/2026
Última modificación:
06/01/2026
Descripción
*** Pendiente de traducción *** QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://cxsecurity.com/issue/WLB-2020080059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186770
- https://packetstormsecurity.com/files/158858
- https://www.howfor.com/
- https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-cookie-authentication-credentials-disclosure
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5578.php



