vendor:
QiHang Media Web Digital Signage
by:
LiquidWorm
7.5
CVSS
HIGH
Cleartext Credentials Disclosure
200
CWE
Product Name: QiHang Media Web Digital Signage
Affected Version From: 3.0.9.0
Affected Version To: 3.0.9.0
Patch Exists: NO
Related CWE: N/A
CPE: a:shenzhen_xingmeng_qihang_media_co._ltd.:qihang_media_web_digital_signage:3.0.9.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows Server 2012 R2 Datacenter, Microsoft Windows Server 2003 Enterprise Edition, ASP.NET 4.0.30319, HowFor Web Server/5.6.0.0, Microsoft ASP.NET Web QiHang IIS Server
2020
QiHang Media Web Digital Signage 3.0.9 – Cleartext Credential Disclosure
The application suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/User/User.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
Mitigation:
Ensure that the application is not exposing any sensitive information in plaintext.