FixVibe

critical

QCubed PHP Object Injection in profile.php (CVE-2020-24914)

QCubed releases before 3.2 are affected by a profile.php PHP object-injection advisory. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.

CVE-2020-24914GHSA-7w3c-jgh7-cwjwGHSA-7w3c-jgh7-cwjwCWE-502CWE-915

QCubed versions before 3.2 are covered by a critical advisory for PHP object injection in the profiler endpoint [S1][S2][S3][S5].

Root Cause

The advisory describes profile.php processing untrusted profiler data with PHP deserialization in affected releases [S4][S5]. PHP object injection risk depends on the deployed code path and available gadget classes, so dependency evidence should be treated as patch-priority advisory context rather than automatic proof of code execution.

Impact

If a vulnerable QCubed deployment exposes the profiler endpoint and accepts untrusted serialized data, attackers may be able to trigger application object lifecycle behavior and, in some deployments, reach remote code execution [S1][S2][S5]. The practical impact depends on deployment exposure, access controls, installed classes, and whether a downstream build backported the fix without changing package version.

Affected Versions

GitHub Advisory and OSV list the Packagist package qcubed/qcubed as affected through 3.1.1 and fixed in 3.2 [S2][S3]. NVD also tracks CVE-2020-24914 for QCubed versions up to and including 3.1.1 [S1].

Fixes and Mitigations

Upgrade qcubed/qcubed to 3.2 or newer, regenerate composer.lock, rebuild deployment artifacts, and verify the deployed PHP host or container no longer contains the affected framework version [S2][S3][S4]. Disable, remove, authenticate, or restrict QCubed profiling functionality while rollout completes.

How FixVibe covers it

FixVibe's GitHub repo scans flag Composer evidence that qcubed/qcubed resolves below 3.2, so you can upgrade.