FixVibe

critical

Unauthenticated SQL Injection in QCubed profile.php (CVE-2020-24913)

CVE-2020-24913 affects QCubed releases before 3.2 through profile.php SQL injection risk. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.

CVE-2020-24913GHSA-8fj6-pc5r-347qGHSA-8fj6-pc5r-347qCWE-89

Impact

CVE-2020-24913 affects QCubed releases before 3.2. Public advisories describe unauthenticated SQL injection risk in the framework profiler endpoint, which can put application database confidentiality, integrity, and availability at risk when the affected code is deployed and reachable [S1][S2][S3][S4].

Root Cause

The issue is in QCubed's profiling functionality. The advisory data maps the vulnerable package to qcubed/qcubed on Packagist and lists affected versions before the 3.2 patched release [S2][S3].

How FixVibe covers it

FixVibe's GitHub repo scans flag composer.lock and composer.json entries for qcubed/qcubed versions or constraints affected by CVE-2020-24913 / GHSA-8fj6-pc5r-347q, with the file, version, affected range and fixed version.

Fixes

Upgrade qcubed/qcubed to 3.2 or newer, regenerate composer.lock, rebuild every PHP host, container image, vendor directory, cache, or copied source tree that installs QCubed, and rerun the FixVibe GitHub repo scan [S2][S3]. If profiling functionality has been exposed, disable, remove, authenticate, or trusted-network restrict it while rollout completes, and review database access logs according to your incident-response policy.