Vulnerability Description
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forlogic | Qualiex | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/underprotection/CVE-2020-24029Third Party Advisory
- https://qualiex.comProductVendor Advisory
- https://github.com/underprotection/CVE-2020-24029Third Party Advisory
- https://qualiex.comProductVendor Advisory
FAQ
What is CVE-2020-24029?
CVE-2020-24029 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspect...
How severe is CVE-2020-24029?
CVE-2020-24029 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24029?
Check the references section above for vendor advisories and patch information. Affected products include: Forlogic Qualiex.