S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-24912 Scanner

CVE-2020-24912 scanner - Cross-Site Scripting (XSS) vulnerability in Qcubed

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-24912
6.1
CVSS

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Qcubed is a PHP web development framework used for building websites and web applications. It is known for its flexibility, ease of use, and speed of development. With a comprehensive set of features, Qcubed offers developers an intuitive, object-oriented programming model that enables them to develop scalable, robust, and secure web applications.

One of the vulnerabilities detected in Qcubed is the XSS vulnerability with CVE ID CVE-2020-24912. This vulnerability was found in the profile.php file and is triggered via the stQuery parameter. The vulnerability allows unauthenticated attackers to exploit the website and steal sessions of authenticated users.

An attacker can take advantage of this vulnerability to inject malicious code into the website, thereby stealing sensitive information, such as login credentials, session cookies, and other personal data. This can violate user privacy and harm the reputation of the website, leading to the loss of trust of users and clients. In the worst-case scenario, an attacker can cause a website to crash or become inaccessible.

In conclusion, with the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets, just like the CVE-2020-24912 vulnerability detected in Qcubed. It is important to stay vigilant and keep our web development frameworks and applications secure to avoid falling victim to attacks that can cause damage to our reputation and financial losses. By following best practices and utilizing the right tools, we can ensure that our digital assets are safe and secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to follow the following steps:

  • Use the latest version of Qcubed.
  • Implement a web application firewall on the server.
  • Use input validation to ensure only legitimate data is entered.
  • Sanitize user input to prevent malicious code injection.
  • Regularly check the security of the website and software used.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-24912 scanner - Cross-Site Scripting (XSS) vulnerability in Qcubed | S4E