PT-2021-11086 · Qcubed · Qcubed

Published

2021-03-04

·

Updated

2025-07-17

·

CVE-2020-24914

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: qcubed versions 3.1.1 and earlier
Description: A PHP object injection bug in profile.php unserializes the untrusted data of the strProfileData POST-variable, allowing an unauthenticated attacker to execute code via a crafted POST request.
Recommendations: For versions 3.1.1 and earlier, consider disabling the profile.php functionality until a patch is available to prevent exploitation of the PHP object injection bug. Restrict access to the strProfileData POST-variable to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2020-24914
GHSA-7W3C-JGH7-CWJW

Affected Products

Qcubed