CVE-2020-36897
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary system commands on the server.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- howfor/qihang media web digital signage
- Source
- disclosure@vulncheck.com
References
- http://www.howfor.comProduct
- https://www.exploit-db.com/exploits/48751Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-remote-code-executionThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5582.phpExploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5582.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.