ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."
History

Tue, 14 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Description ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-14T12:57:12.807Z

Reserved: 2020-08-13T00:00:00.000Z

Link: CVE-2020-24028

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-02T17:15:12.077

Modified: 2025-10-14T13:15:32.383

Link: CVE-2020-24028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.