ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.
- Announcement (to Vendor): 2020-07-12
- Public disclosure date: 2020-08-31
Insecure Permissions
ForLogic
- Qualiex - v1
- Qualiex - v3
- Other versions may be affected, especially in the same family (not tested yet)
Qualiex
Remote
True
True
Authenticated permission bypass permits password changes, user creation and privilege escalation on user's information update
True
Mauricio Santos (R&D UnderProtection), Claudemir Nunes (R&D UnderProtection) and Hesron Hori (R&D UnderProtection)
Forlogic - Vendor's Information Security Team who collaborated to a coordinated disclosure