Showing 1 vulnerability on this page for qcubed

Signals CISA KEV Ransomware Nuclei
qcubed vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

qcubed PHP object injection

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

CWE-502CWE-915Mar 4, 2021
CVSS9.8v3.1EPSS5.07%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX