Impact
QuickCMS lacks CSRF protection across multiple endpoints, meaning every form could be exploited. This vulnerability, a classic Cross‑Site Request Forgery (CWE‑352), allows an attacker to craft a malicious web page that, when visited by a logged‑in user, automatically sends a POST request using the victim’s credentials. This flaw allows the attacker to perform any state‑changing operation the victim is authorized to execute, such as editing or deleting content.
Affected Systems
OpenSolution QuickCMS is affected. Versions prior to 6.8 are vulnerable; 6.8 contains a fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.1, indicating moderate impact. The EPSS score is below 1 %, indicating a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is a social engineering or phishing scenario where the victim visits a malicious site while logged into the CMS; this inference is based on the description of the payload being automatically sent with the victim’s privileges.
OpenCVE Enrichment