CVE-2020-24914
Critical · CVSS 9.8qcubed/qcubed — PHP Object Injection / Deserialization RCE (CWE-502)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-502
Description
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.
Search profile — drives PoC discovery
Symbols profile.phpstrProfileDataunserialize__wakeup__destructPOST
Keywords CVE-2020-24914qcubedPHP object injectionunserialize strProfileDataprofile.php deserializationqcubed RCEqcubed 3.1.1 exploitpackagist qcubed object injection
Versions: all versions including 3.1.1
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0cyb3r-w0lf/nuclei-template-collection needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Packagist | qcubed/qcubed | 0 → 3.2 |
References
- http://packetstormsecurity.com/files/161758/QCubed-3.1.1-PHP-Object-Injection.html
- http://seclists.org/fulldisclosure/2021/Mar/28
- https://tech.feedyourhead.at/content/QCubed-PHP-Object-Injection-CVE-2020-24914
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-01
- http://qcubed.com
- http://seclists.org/fulldisclosure/2021/Mar/28
- https://tech.feedyourhead.at/content/QCubed-PHP-Object-Injection-CVE-2020-24914
- https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-01
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z