CVE-2020-24029

CRITICAL

ForLogic Qualiex v1/v3 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-24029. PoCs published by redteambrasil, underprotection.

AI-analyzed exploit summary This repository contains a writeup for CVE-2020-24029, detailing an incorrect access control vulnerability in ForLogic Qualiex v1 and v3 that allows unauthenticated password changes, leading to privilege escalation and information disclosure.

Description

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."

Exploits (2)

nomisec WRITEUP
by redteambrasil · poc
https://github.com/redteambrasil/CVE-2020-24029

This repository contains a writeup for CVE-2020-24029, detailing an incorrect access control vulnerability in ForLogic Qualiex v1 and v3 that allows unauthenticated password changes, leading to privilege escalation and information disclosure.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by underprotection · poc
https://github.com/underprotection/CVE-2020-24029

This repository contains a writeup for CVE-2020-24029, detailing an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows remote attackers to bypass authentication and escalate privileges or disclose information via a simple request.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Product, Vendor Advisory
https://qualiex.com

Scores

CVSS v3 9.8
EPSS 0.0197
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
forlogic/qualiex 1.0
forlogic/qualiex 3.0
Published Sep 02, 2020
Tracked Since Feb 18, 2026