Description
ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."
Published: 2020-09-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-16764 ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.
History

Tue, 14 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Description ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

Subscriptions

Forlogic Qualiex
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-14T12:57:12.807Z

Reserved: 2020-08-13T00:00:00.000Z

Link: CVE-2020-24028

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-02T17:15:12.077

Modified: 2025-10-14T13:15:32.383

Link: CVE-2020-24028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses