CVE-2020-36898

Source
https://cve.org/CVERecord?id=CVE-2020-36898
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36898.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36898
Published
2025-12-10T21:16:02.360Z
Modified
2026-03-15T22:38:14.127007Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. Attackers can exploit the 'data' parameter by sending a POST request with file paths to delete arbitrary files with web server permissions using directory traversal sequences.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.9"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36898.json"