EXPOSURES › CVE-2020-24914
CVE-2020-24914
CRITICAL
DETAIL
SourceNVD · cve
Published2021-03-04
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24914 ↗
⚡ RCE
SHAME 50/100
rce
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
Widely condemned due to unauthenticated RCE in all versions
Damning disclosure of unauthenticated RCE in all versions
"A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request."
Neutral listing of vulnerability in database
Neutral listing of vulnerability in database
Irrelevant content unrelated to qcubed
Irrelevant content unrelated to qcubed
Irrelevant content unrelated to qcubed
Irrelevant content unrelated to qcubed
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.