{"id":"CVE-2020-24912","title":"A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.","summary":"A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"qcubed","product":"qcubed","affected":["qcubed <= 3.1.1"],"published":"2021-03-04","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-24912","references":[{"url":"http://packetstormsecurity.com/files/161763/QCubed-3.1.1-Cross-Site-Scripting.html","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2021/Mar/30","label":"cve@mitre.org"},{"url":"https://tech.feedyourhead.at/content/QCubed-Cross-Site-Scripting-CVE-2020-24912","label":"cve@mitre.org"},{"url":"https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-03","label":"cve@mitre.org"},{"url":"http://qcubed.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2021/Mar/30","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tech.feedyourhead.at/content/QCubed-Cross-Site-Scripting-CVE-2020-24912","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-03","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.0634,"epssPercentile":0.93321,"ingestedAt":"2026-07-05T02:00:01.419Z","exploits":{"nuclei":["CVE-2020-24912"],"checkedAt":"2026-09-23T07:13:17.578Z"},"exploitAvailable":true,"slug":"CVE-2020-24912","body":"## Overview\n\nA reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.\n\n## Affected\n\n- `qcubed <= 3.1.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":33.6,"likelihood":1.3,"exploitation":12,"ransomware":0},"changes":[{"seq":4488,"id":"CVE-2020-24912","ts":1788887184151,"field":"exploit_available","old":"false","new":"true"},{"seq":3371,"id":"CVE-2020-24912","ts":1788886302949,"field":"exploit_available","old":"true","new":"false"},{"seq":2226,"id":"CVE-2020-24912","ts":1788882972586,"field":"exploit_available","old":"false","new":"true"},{"seq":1255,"id":"CVE-2020-24912","ts":1788882384204,"field":"exploit_available","old":"true","new":"false"},{"seq":369,"id":"CVE-2020-24912","ts":1788881819578,"field":"exploit_available","old":"false","new":"true"}]}