CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2020-24914

Critical · CVSS 9.8

qcubed/qcubed — PHP Object Injection / Deserialization RCE (CWE-502)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-502

Description

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

Search profile — drives PoC discovery

Symbols profile.phpstrProfileDataunserialize__wakeup__destructPOST
Keywords CVE-2020-24914qcubedPHP object injectionunserialize strProfileDataprofile.php deserializationqcubed RCEqcubed 3.1.1 exploitpackagist qcubed object injection
Versions: all versions including 3.1.1

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Packagist qcubed/qcubed 0 → 3.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z