CVE-2020-24030

CRITICAL

ForLogic Qualiex v1/v3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-24030. PoCs published by redteambrasil, underprotection.

AI-analyzed exploit summary This repository contains a writeup for CVE-2020-24030, detailing a weak token expiration vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows remote unauthenticated privilege escalation and sensitive data access via token reuse.

Description

ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."

Exploits (2)

nomisec WRITEUP
by redteambrasil · poc
https://github.com/redteambrasil/CVE-2020-24030

This repository contains a writeup for CVE-2020-24030, detailing a weak token expiration vulnerability in ForLogic Qualiex v1 and v3. The vulnerability allows remote unauthenticated privilege escalation and sensitive data access via token reuse.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
No auth needed
Prerequisites: Access to a valid token from a previous session
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by underprotection · poc
https://github.com/underprotection/CVE-2020-24030

This repository contains a writeup for CVE-2020-24030, detailing a weak token expiration vulnerability in ForLogic Qualiex v1 and v3, allowing remote unauthenticated privilege escalation and sensitive data access via token reuse.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ForLogic Qualiex v1 and v3
No auth needed
Prerequisites: Access to a valid token
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Product, Vendor Advisory
https://qualiex.com

Scores

CVSS v3 9.8
EPSS 0.0267
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-672
Status published
Products (2)
forlogic/qualiex 1.0
forlogic/qualiex 3.0
Published Sep 02, 2020
Tracked Since Feb 18, 2026