← back
CVE-2020-24912

CVE-2020-24912

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 6.3%
exploitation probability
6.3%top 7% of all CVEs
observed exploitation
nono source reports it
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.
Affected products
n/a · n/a