Unauthenticated File Disclosure Vulnerability in ReQuest Serious Play Media Player
CVE-2020-36878
Key Information:
- Vendor
Request Serious Play Llc
- Vendor
- CVE Published:
- 5 December 2025
Badges
What is CVE-2020-36878?
The ReQuest Serious Play Media Player 3.0 has a vulnerability that allows attackers to exploit an unauthenticated file disclosure issue via the 'file' parameter. Inadequate verification of user input can lead to unauthorized access to sensitive web log files. Malicious actors can potentially manipulate this vulnerability to access and expose private information stored on the server, posing significant risks to data security.
Affected Version(s)
ReQuest Serious Play Media Player 3.0.0
ReQuest Serious Play Media Player 2.1.0.831
ReQuest Serious Play Media Player 1.5.2.822
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
