Junglewise Threat Intelligence

CVE-2026-63302: OpenSolution Quick.CMS Local File Inclusion in admin.php

CVE-2026-63302 · Severity: info · CVSS 5.1 · Published 2026-07-28

Technologies: OpenSolution Quick.CMS. Vendors: OpenSolution.

Executive brief

Quick.CMS is a content management system used to build and manage websites. A security flaw in the administration panel allows an authorized administrator to view internal server directory structures and file paths that should normally be hidden. While this could help an attacker map out the server for further attacks, the vendor has stated they do not intend to release a fix as they consider the risk to be very low.

Technical details

A Local File Inclusion (LFI) vulnerability exists in Quick.CMS through version 6.8.0 within the 'admin.php' endpoint. The application fails to properly sanitize the 'p' parameter, allowing an authenticated attacker with administrative privileges to include arbitrary files from the application's directory structure. Successful exploitation results in path disclosure, revealing the server's directory structure and absolute file paths. The vendor has acknowledged the report but determined that a fix is not necessary due to the requirement for administrative privileges.

Affected products

  • OpenSolution Quick.CMS Through 6.8.0

Timeline

  • 2026-07-28: disclosed: Disclosed by CERT Polska
  • 2026-07-28: advisory

References

Related threats