CVE-2020-36897

Source
https://cve.org/CVERecord?id=CVE-2020-36897
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36897.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36897
Published
2025-12-10T21:16:02.210Z
Modified
2026-03-14T14:47:38.028849Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary system commands on the server.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.9"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36897.json"