CVE-2020-24028
Last modified
CVE-2020-24028 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. EPSS estimates a 2.28% chance of exploitation in the next 30 days.
Description
ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Forlogic | Qualiex | 1.0 |
| Forlogic | Qualiex | 3.0 |
References
- https://forlogic.netVendor Advisory
- https://github.com/underprotection/CVE-2020-24028Third Party Advisory
- https://qualiex.comProduct, Vendor Advisory
- https://forlogic.netVendor Advisory
- https://github.com/underprotection/CVE-2020-24028Third Party Advisory
- https://qualiex.comProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24028?
How severe is CVE-2020-24028?
How do I fix CVE-2020-24028?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-24007Umanni RH 1.0 does not limit the number of authentication at…9.8
- CVE-2020-24008Umanni RH 1.0 has a user enumeration vulnerability. This iss…5.3
- CVE-2020-24020Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute…8.8
- CVE-2020-24025Certificate validation in node-sass 2.0.0 to 4.14.1 is disab…5.3
- CVE-2020-24026TinyShop, a free and open source mall based on RageFrame2, h…6.1
- CVE-2020-24027In Live Networks, Inc., liblivemedia version 20200625, there…9.8
- CVE-2020-24029Because of unauthenticated password changes in ForLogic Qual…9.8
- CVE-2020-24030ForLogic Qualiex v1 and v3 has weak token expiration. This a…9.8
- CVE-2020-24032tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances…9.8
- CVE-2020-24033An issue was discovered in fs.com S3900 24T4S 1.7.0 and earl…8.8
- CVE-2020-24034Sagemcom F@ST 5280 routers using firmware version 1.150.61 h…8.8
- CVE-2020-24036PHP object injection in the Ajax endpoint of the backend in …8.8
Are you affected by CVE-2020-24028?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
