CVE-2020-24913
critical · 9.8A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
9.8
CVSS
40.9%
EPSS (exploit prob.)
99th
EPSS percentile
2021-03-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| qcubed | qcubed | <= 3.1.1 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/161759/QCubed-3.1.1-SQL-Injection.html
- http://seclists.org/fulldisclosure/2021/Mar/29
- http://seclists.org/fulldisclosure/2021/Mar/30
- https://tech.feedyourhead.at/content/QCubed-SQL-Injection-CVE-2020-24913
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-02
- http://seclists.org/fulldisclosure/2021/Mar/29
- http://seclists.org/fulldisclosure/2021/Mar/30
- https://tech.feedyourhead.at/content/QCubed-SQL-Injection-CVE-2020-24913
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-02
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-24913