Vulnerability Description
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qcubed | Qcubed | <= 3.1.1 |
Related Weaknesses (CWE)
References
- http://qcubed.comProduct
- http://seclists.org/fulldisclosure/2021/Mar/30ExploitMailing ListThird Party Advisory
- https://tech.feedyourhead.at/content/QCubed-Cross-Site-Scripting-CVE-2020-24912ExploitPatchThird Party Advisory
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sExploitPatchThird Party Advisory
- http://qcubed.comProduct
- http://seclists.org/fulldisclosure/2021/Mar/30ExploitMailing ListThird Party Advisory
- https://tech.feedyourhead.at/content/QCubed-Cross-Site-Scripting-CVE-2020-24912ExploitPatchThird Party Advisory
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sExploitPatchThird Party Advisory
FAQ
What is CVE-2020-24912?
CVE-2020-24912 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticat...
How severe is CVE-2020-24912?
CVE-2020-24912 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24912?
Check the references section above for vendor advisories and patch information. Affected products include: Qcubed Qcubed.