QiHang Media Web Digital Signage Credential Disclosure Scanner
Targets the web interface's configuration endpoint where credentials are stored in plaintext, allowing attackers to extract admin login details.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
19 days 15 hours
Scan only one
URL
Toolbox
QiHang Media Web Digital Signage is a platform used by organizations to manage and deploy digital signage content across multiple screens. Marketing teams, IT administrators, and service providers rely on it to schedule and display multimedia in retail stores, corporate offices, and public venues. The software offers remote management via a web interface, enabling users to update content in real-time.
The credential disclosure vulnerability arises when the application stores administrative credentials in plaintext within configuration files or transmits them over unencrypted channels. This occurs due to inadequate security practices during development, such as hardcoding passwords or failing to implement encryption for sensitive data. Attackers can exploit this by accessing exposed endpoints or intercepting network traffic.
Specifically, the vulnerability affects the /config endpoint in QiHang Media Web Digital Signage version 3.0.9, where credentials are stored in a JSON file without encryption. By sending a GET request to this endpoint, an attacker can retrieve the admin username and password in plaintext. No authentication is required to access this sensitive data.
If exploited, an attacker gains full administrative access to the digital signage system, allowing them to modify displayed content, disrupt operations, or deploy malicious media. This can lead to reputational damage, financial loss, or physical security risks in public spaces. The high CVSS score of 8.3 reflects the critical nature of this vulnerability.