ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. | ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope." |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-14T12:57:12.807Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-24028

No data.

Status : Modified
Published: 2020-09-02T17:15:12.077
Modified: 2025-10-14T13:15:32.383
Link: CVE-2020-24028

No data.

No data.