QiHang Media Web Digital Signage Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability in QiHang Media Web Digital Signage version 3.0.9 has been identified, allowing remote attackers to intercept user authentication credentials. This issue arises from the cleartext transmission of sensitive information in cookies, which can be exploited through man-in-the-middle attacks. The vulnerability was tested on multiple Windows Server editions and involves the HowFor Web Server and Microsoft ASP.NET Web QiHang IIS Server.

Impact

Exploitation of this vulnerability allows for the interception of HTTP cookie authentication credentials, which could be misused to bypass security measures or gain unauthorized access to user accounts.

Reproduction

The vulnerability can be reproduced by sending a POST request to 'QH.aspx' without encryption. The intercepted request will reveal cookies containing sensitive authentication information, such as the username and password.

Added: Jan 6, 2026, 4:43 PM
Updated: Jan 6, 2026, 4:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.3
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.