Executive brief
Quick.CMS is a content management system used to build and manage websites. A security flaw allows the deletion of the website's primary language, which causes the entire application to stop functioning (Denial of Service). While the administrative interface tries to hide this option, the underlying system does not actually block the request, meaning a malicious actor or a tricked administrator could crash the site.
Technical details
A vulnerability classified as Client-Side Enforcement of Server-Side Security (CWE-602) exists in Quick.CMS through version 6.8.0. While the administrative UI omits the option to delete the primary language, the backend API endpoint fails to perform a corresponding server-side check to prevent this action. An authenticated administrator can send a direct HTTP request to the language-deletion endpoint to remove the primary language, resulting in a persistent Denial of Service. Furthermore, this can be exploited by an unauthenticated attacker via Cross-Site Request Forgery (CSRF) if an authenticated admin visits a malicious link. The vendor has stated they do not intend to release a fix.
Affected products
- OpenSolution Quick.CMS All through 6.8.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory: Advisory published by CERT.PL