CVE-2020-36878: Request Serious Play Llc Request Serious Play Media Player

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.

Affected products

  • Request Serious Play Llc Request Serious Play Media Player: version 3.0.0 only; version 2.1.0.831 only; version 1.5.2.822 only; version 1.5.2.821 only; version 1.5.1.820 only

Published 2025-12-05. Last modified 2026-06-17.