EXPOSURES › CVE-2020-24913
CVE-2020-24913
CRITICAL
DETAIL
SourceNVD · cve
Published2021-03-04
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24913 ↗
SHAME 35/100
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
Widely condemned for critical SQL injection flaw in all versions
Apple accuses OpenAI employee of hacking
"BREAKING: Apple accuses an OpenAI employee of hacking its systems, downloading unreleased product files, & celebrating the breach as 'so funny.'"
Critical vulnerability disclosed
"A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request."
Accenture confirms intrusion after hacker claims 35GB data breach
"Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach"
Critical RCE flaw exposed 84,000 servers
"Over 84,000 Roundcube webmail servers remain exposed to a critical RCE flaw (CVE-2025-49113) despite a June 2025 patch fixing the vulnerability."
Exploited by hackers
"Hackers exploit Roundcube flaw to spy on academic researchers"
AI agent vulnerability disclosed
"'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets"
Listed as critical vulnerability
"CVE 2020-24913 is a critical vulnerability in qcubed."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.