CVE-2020-24914: Improperly Controlled Modification of Dynamically-Determined Object Attributes
(updated )
A PHP object injection bug in profile.php
in qcubed deserializes the untrusted data of the POST-variable strProfileData
and allows an unauthenticated attacker to execute code via a crafted POST request.
References
Detect and mitigate CVE-2020-24914 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →