---
id: CVE-2020-36895
title: >-
  EIBIZ i-Media Server Digital Signage 3.8.0 Unauthenticated Configuration
  Disclosure
summary: >-
  EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated
  configuration disclosure vulnerability that allows remote attackers to access
  sensitive configuration files via direct object reference. Attackers can
  retrieve the Si…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cvssSource: cna
cwe:
  - CWE-639
vendor: 'EIBIZ Co.,Ltd.'
product: i-Media Server Digital Signage
affected:
  - i-media_server_digital_signage <= 3.8.0
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-11T15:55:49.999957Z'
exploitAvailable: true
published: '2025-12-10'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:33.152Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2020-36895'
references:
  - url: 'https://www.exploit-db.com/exploits/48764'
    label: ExploitDB-48764
  - url: 'http://www.eibiz.co.th'
    label: 'EIBIZ Co.,Ltd. Product Homepage'
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5583.php'
    label: Zero Security Advisory ZSL-2020-5583
  - url: >-
      https://www.vulncheck.com/advisories/eibiz-i-media-server-digital-signage-unauthenticated-configuration-disclosure
    label: >-
      VulnCheck Advisory: EIBIZ i-Media Server Digital Signage 3.8.0
      Unauthenticated Configuration Disclosure
tags:
  - cve.org
  - exploit-available
epss: 0.00734
epssPercentile: 0.52701
ingestedAt: '2026-10-01T15:48:17.878Z'
---

## Overview

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.

## Affected

- `i-media_server_digital_signage <= 3.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
