Lucene search

K
osvGoogleOSV:GHSA-7W3C-JGH7-CWJW
HistoryMay 24, 2022 - 5:43 p.m.

qcubed PHP object injection

2022-05-2417:43:37
Google
osv.dev
8

7.5 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

87.8%

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable “strProfileData” and allows an unauthenticated attacker to execute code via a crafted POST request.

7.5 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

87.8%