CVE-2020-24028

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."
References
Link Resource
https://forlogic.net Vendor Advisory
https://github.com/underprotection/CVE-2020-24028 Third Party Advisory
https://qualiex.com Product Vendor Advisory
https://forlogic.net Vendor Advisory
https://github.com/underprotection/CVE-2020-24028 Third Party Advisory
https://qualiex.com Product Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:forlogic:qualiex:1.0:*:*:*:*:*:*:*
cpe:2.3:a:forlogic:qualiex:3.0:*:*:*:*:*:*:*

History

14 Oct 2025, 13:15

Type Values Removed Values Added
Summary (en) ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. (en) ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

Information

Published : 2020-09-02 17:15

Updated : 2025-10-14 13:15


NVD link : CVE-2020-24028

Mitre link : CVE-2020-24028

CVE.ORG link : CVE-2020-24028


JSON object : View

Products Affected

forlogic

  • qualiex