CVE-2020-36877 PUBLISHED

ReQuest Serious Play F3 Media Server <= 7.0.3 code execution

Assigner: VulnCheck
Reserved: 05.12.2025 Published: 05.12.2025 Updated: 12.12.2025

ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor ReQuest Serious Play LLC
Product ReQuest Serious Play Pro
Versions Default: unknown
  • Version 7.0.3.4968 is affected
Vendor ReQuest Serious Play LLC
Product ReQuest Serious Play
Versions Default: unknown
  • Version 7.0.2.4954 is affected
  • Version 6.5.2.4954 is affected
  • Version 6.4.2.4681 is affected
  • Version 6.3.2.4203 is affected
  • Version 2.0.1.823 is affected

Credits

  • LiquidWorm, Gjoko 'LiquidWorm' Krstic, Macedonian Information Security Research and Development Laboratory, Zero Science Lab - https://www.zeroscience.mk - @zeroscience finder

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE