6.1
CVSSv3

CVE-2020-24912

Published: 04/03/2021 Updated: 22/03/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated malicious users to steal sessions of authenticated users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qcubed qcubed

Exploits

QCubed versions 311 and below suffer from a cross site scripting vulnerability ...