CVE-2020-36878
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-05
Last updated on: 2025-12-08
Assigner: VulnCheck
Description
Description
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| request | serious_play_media_player | 1.5.2.821 |
| request | serious_play_media_player | 2.1.0.831 |
| request | serious_play_media_player | 1.5.1.820 |
| request | serious_play_media_player | 3.0.0 |
| request | serious_play_media_player | 1.5.2.822 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |