Impact
Quick.CMS is vulnerable to Local File Inclusion via the p parameter in the admin.php endpoint. This flaw, categorized as CWE-98, allows an attacker with administrator privileges to include arbitrary files located within the application’s directory. Successful exploitation is limited to disclosure of the server’s directory structure and absolute file paths; it does not grant code execution or broader system compromise.
Affected Systems
The impacted product is Quick.CMS from OpenSolution. No specific version information is provided for the affected releases.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate impact, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated admin credentials, and the vendor has assessed the likelihood as very low, stating that a fix is not necessary at this time.
OpenCVE Enrichment