CVE-2020-36895

HIGH

EIBIZ i-Media Server Digital Signage 3.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/48764

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
eibiz/i-media_server_digital_signage 3.8.0
Published Dec 10, 2025
Tracked Since Feb 18, 2026