CVE-2020-24912
qcubed reflected cross-site scripting (XSS) vulnerability
Record summary
CVE-2020-24912 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
qcubed/qcubedBrowse Packagist / qcubed/qcubed | GitHub Advisory | Before 3.2 · Fixed in 3.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMQCube Cross-Site-ScriptingCVSS 6.1
A reflected cross-site scripting vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery