Impact
A blind SQL injection flaw exists in the administration panel of Quick.CMS, where input from a high‑privileged user is insufficiently neutralized. An attacker who gains such privileges can inject malicious SQL through various fields, bypassing client‑side validation and potentially corrupting or deleting database contents. The weakness falls under CWE‑89 and can compromise the confidentiality and integrity of stored data.
Affected Systems
OpenSolution Quick.CMS version 6.8 is confirmed vulnerable, and the vendor notes that other releases may also be affected. The product is a content‑management system with an administrative interface that provides extensive modification capabilities.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1 and an EPSS probability of less than 1 %. It is not listed in the CISA KEV catalog. The attack requires an attacker to be authenticated with high‑privilege access, which the application already grants for administration tasks. Consequently, the risk is moderate, but the lack of a current official fix and the potential for database damage warrant careful assessment.
OpenCVE Enrichment