Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29576
HistoryMar 05, 2021 - 1:04 a.m.

Untrusted Object Deserialization

2021-03-0501:04:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.017 Low

EPSS

Percentile

87.8%

Qcubed is vulnerable to untrusted object deserialization. An attacker is able to inject untrusted PHP object of the POST-variable “strProfileData” and execute code via a malicious POST request.

CPENameOperatorVersion
qcubed/qcubedlev3.1.1