CVE-2020-24029
CRITICALForLogic Qualiex v1/v3 - Info Disclosure
Title source: llmDescription
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."
Exploits (2)
Scores
CVSS v3
9.8
EPSS
0.0083
EPSS Percentile
74.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (2)
forlogic/qualiex
1.0
forlogic/qualiex
3.0
Published
Sep 02, 2020
Tracked Since
Feb 18, 2026