Skip to content
COOEY

EXPOSURES › CVE-2020-24914

CVE-2020-24914

CRITICAL
DETAIL
SourceNVD · cve Published2021-03-04 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24914 ↗
⚡ RCE SHAME 50/100 rce

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widely condemned due to unauthenticated RCE in all versions
cooey ↗ severe-fallout -0.90
Damning disclosure of unauthenticated RCE in all versions
"A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request."
www.cvefind.com ↗ severe-fallout -0.50
Neutral listing of vulnerability in database
app.opencve.io ↗ severe-fallout -0.50
Neutral listing of vulnerability in database
chromereleases.googleblog.com ↗ severe-fallout +0.00
Irrelevant content unrelated to qcubed
www.techradar.com ↗ severe-fallout +0.00
Irrelevant content unrelated to qcubed
www.pcworld.com ↗ severe-fallout +0.00
Irrelevant content unrelated to qcubed
classactionu.org ↗ severe-fallout +0.00
Irrelevant content unrelated to qcubed
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.