packetstormsecurity.com
http://packetstormsecurity.com/files/161758/QCubed-3.1.1-PHP-Object-Injection.html CVE-2020-24914
CRITICAL
qcubed PHP object injection
Record summary
CVE-2020-24914 has a selected CVSS score of 9.8 (critical).
Description
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
qcubedBrowse qcubed / qcubed | VulnCheck | Version data not supplied | |
qcubed/qcubedBrowse Packagist / qcubed/qcubed | GitHub Advisory | Before 3.2 · Fixed in 3.2 | affected |
References
8qcubed.com
http://qcubed.com/ 20210312 [AIT-SA-20210215-01] CVE-2020-24914: QCubed PHP Object Injectionmailing list
http://seclists.org/fulldisclosure/2021/Mar/28 github.com
https://github.com/qcubed/qcubed github.com
https://github.com/qcubed/qcubed/pull/1320/files nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24914 tech.feedyourhead.at
https://tech.feedyourhead.at/content/QCubed-PHP-Object-Injection-CVE-2020-24914 ait.ac.at
https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-01