CVE-2020-24028

HIGH

ForLogic Qualiex v1-v3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-24028. PoCs published by redteambrasil, underprotection.

AI-analyzed exploit summary This repository contains a detailed writeup for CVE-2020-24028, describing an insecure permissions vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows authenticated customers to escalate privileges via user creation, password changes, or permission updates.

Description

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

Exploits (2)

nomisec WRITEUP
by redteambrasil · poc
https://github.com/redteambrasil/CVE-2020-24028

This repository contains a detailed writeup for CVE-2020-24028, describing an insecure permissions vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows authenticated customers to escalate privileges via user creation, password changes, or permission updates.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
Auth required
Prerequisites: Authenticated access to the Qualiex application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by underprotection · poc
https://github.com/underprotection/CVE-2020-24028

This repository contains a writeup for CVE-2020-24028, detailing an insecure permissions vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows authenticated customers to escalate privileges via user creation, password changes, or permission updates.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
Auth required
Prerequisites: Authenticated access to the Qualiex application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory
https://forlogic.net
Product, Vendor Advisory
https://qualiex.com

Scores

CVSS v3 8.8
EPSS 0.0228
EPSS Percentile 80.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
forlogic/qualiex 1.0
forlogic/qualiex 3.0
Published Sep 02, 2020
Tracked Since Feb 18, 2026