CVE-2020-24913
🔴 Łataj teraz
Wstrzyknięcie SQL w qcubed umożliwia nieautoryzowanym atakującym dostęp do bazy danych.
CVSS
9.8
EPSS
40.6%
Exploit
poc
Vendor
qcubed
Opis źródłowy (NVD)
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
exploit sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 40.6% |
| Opublikowano (NVD) | 2021-03-04 13:15:15 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 00:17:01 UTC |
Referencje
- http://packetstormsecurity.com/files/161759/QCubed-3.1.1-SQL-Injection.html (cve@mitre.org)
- http://seclists.org/fulldisclosure/2021/Mar/29 (cve@mitre.org) [Exploit, Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Mar/30 (cve@mitre.org) [Exploit, Mailing List, Third Party Advisory]
- https://tech.feedyourhead.at/content/QCubed-SQL-Injection-CVE-2020-24913 (cve@mitre.org) [Exploit, Patch, Third Party Advisory]
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-02 (cve@mitre.org) [Exploit, Patch, Third Party Advisory]