CVE-2020-24913
Critical · CVSS 9.8qcubed/qcubed — SQL Injection (CWE-89)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-89
Description
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
Search profile — drives PoC discovery
Symbols profile.phpstrQueryPOST
Keywords CVE-2020-24913qcubedSQL injectionprofile.phpstrQueryqcubed SQL injectionQCubed 3.1.1
Versions: all versions including 3.1.1
Ranked PoCs (4) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0
- ★ 0cyb3r-w0lf/nuclei-template-collection needs reviewtrickest
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Packagist | qcubed/qcubed | 0 → 3.2 |
References
- http://packetstormsecurity.com/files/161759/QCubed-3.1.1-SQL-Injection.html
- http://seclists.org/fulldisclosure/2021/Mar/29
- http://seclists.org/fulldisclosure/2021/Mar/30
- https://tech.feedyourhead.at/content/QCubed-SQL-Injection-CVE-2020-24913
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-02
- http://qcubed.com
- http://seclists.org/fulldisclosure/2021/Mar/29
- http://seclists.org/fulldisclosure/2021/Mar/30
- https://tech.feedyourhead.at/content/QCubed-SQL-Injection-CVE-2020-24913
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-02
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z