CVE-2020-36914 Details
Description
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.
A vulnerability in QiHang Media Web Digital Signage version 3.0.9 has been identified, allowing remote attackers to intercept user authentication credentials. This issue arises from the cleartext transmission of sensitive information in cookies, which can be exploited through man-in-the-middle attacks. The vulnerability was tested on multiple Windows Server editions and involves the HowFor Web Server and Microsoft ASP.NET Web QiHang IIS Server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 6, 2026CISA-ADP
Assessed Jan 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cxsecurity.com/issue/WLB-2020080059 | [email protected] | ExploitTechnical Description |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/186770 | [email protected] | Advisory |
| https://packetstormsecurity.com/files/158858 | [email protected] | Exploit |
| https://www.howfor.com/ | [email protected] | Vendor |
| https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-cookie-authentication-credentials-disclosure | [email protected] | AdvisoryBundle |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5578.php | [email protected] | AdvisoryExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| QiHang Media Web Digital Signage | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 6, 2026 | New CVE Received | [email protected] |
Volerion