
Proof-of-concept for CVE-2020-24028: authenticated privilege escalation via insecure permissions in ForLogic Qualiex v1 and v3, enabling user creation and password changes.
ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.
Insecure Permissions
ForLogic
Qualiex
Remote
True
True
Authenticated permission bypass permits password changes, user creation and privilege escalation on user's information update
True
Mauricio Santos (R&D UnderProtection), Claudemir Nunes (R&D UnderProtection) and Hesron Hori (R&D UnderProtection)
Forlogic - Vendor's Information Security Team who collaborated to a coordinated disclosure