Executive brief
Quick.CMS is a content management system used to build and manage websites. A security flaw in the administration panel allows high-privileged users to perform unauthorized database operations. While this could lead to data corruption or the bypassing of certain interface restrictions, the vendor has declined to issue a fix, stating that administrative users already possess significant control over the system by design.
Technical details
A Blind SQL injection vulnerability exists in OpenSolution Quick.CMS version 6.8 due to improper neutralization of input within multiple fields of the administration panel. The flaw is reachable by a high-privileged authenticated user via the network. An attacker with administrative access can exploit this to bypass front-end validation controls or perform destructive operations on the underlying database. The vendor has acknowledged the report but stated that remediation is unnecessary because the administrative trust model already grants these users extensive modification capabilities. No patch is currently planned.
Affected products
- OpenSolution Quick.CMS 6.8
Timeline
- 2026-07-29: advisory: Advisory published by CERT.PL and NVD