VYPR
Critical severity9.8NVD Advisory· Published Sep 2, 2020· Updated Jun 17, 2026

CVE-2020-24029

CVE-2020-24029

Description

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • ForLogic/Qualiexllm-fuzzy4 versions
    v1 and v3+ 3 more
    • (no CPE)range: v1 and v3
    • (no CPE)
    • cpe:2.3:a:forlogic:qualiex:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:forlogic:qualiex:3.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.