QiHang Media Web Digital Signage Unauthenticated Arbitrary File Disclosure Vulnerability

Vulnerability

An unauthenticated file disclosure vulnerability has been identified in QiHang Media Web Digital Signage version 3.0.9. The vulnerability allows remote attackers to access sensitive files by exploiting unverified 'filename' and 'path' parameters. This issue occurs in the QH.aspx endpoint, where attackers can manipulate download and getAll actions to read arbitrary files and directory contents without authentication.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive files and directory information on the server.

Reproduction

The vulnerability can be reproduced by sending a GET request to the QH.aspx endpoint with the 'filename' parameter set to traverse directories and access sensitive files, such as the Web.config or Global.asax. Alternatively, a POST request can be sent to the same endpoint with the 'path' parameter to disclose directory contents.

Added: Dec 10, 2025, 9:35 PM
Updated: Dec 10, 2025, 9:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.