CVE-2020-36878
ReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File Disclosure
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
05 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
ReQuest Serious Play LLC · ReQuest Serious Play Media PlayerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →