
Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and information disclosure.
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request.
Incorrect Access Control
ForLogic
Qualiex
Remote
True
True
Unauthenticated password changes publicly available without special requirements (only the correct request)
True
Mauricio Santos (R&D UnderProtection), Claudemir Nunes (R&D UnderProtection) and Hesron Hori (R&D UnderProtection)
Forlogic - Vendor's Information Security Team who collaborated to a coordinated disclosure