Impact
A path traversal flaw in the web root URI component allows an authenticated user with admin privileges to request files located outside the web directory by including dot-dot-slash sequences. This flaw enables the reading of arbitrary files and can expose confidential information. The weakness matches CWE-23 and carries a CVSS score of 5.1, indicating moderate severity.
Affected Systems
The vulnerability is present in OpenSolution Quick.CMS. No specific version range is listed, so any deployment of Quick.CMS should be considered potentially affected until vendor advisories provide further detail.
Risk and Exploitability
The EPSS score of less than 1% signals that exploitation is expected to be rare, and the flaw is not listed in the CISA KEV catalog. Attackers must already possess administrative credentials, limiting the reach. Given the moderate CVSS score and low exploitation probability, the overall risk is moderate but unlikely to be observed in the wild.
OpenCVE Enrichment