Executive brief
Quick.CMS, a content management system used for building websites, contains a security flaw that could allow an administrator to access files they should not be able to see. By manipulating web addresses, a user with administrative privileges can bypass security boundaries to read files located outside of the standard web folder. The software vendor has stated they do not intend to release a fix, as they consider the risk of exploitation to be very low.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Quick.CMS through version 6.8.0. The application fails to properly normalize dot-dot-slash (../) sequences within the URI path component of HTTP requests before resolving the file path. An authenticated attacker with administrative privileges can exploit this to read sensitive files located in directories adjacent to the webroot. The vendor has acknowledged the report but determined that no patch is necessary, citing a low likelihood of exploitation.
Affected products
- OpenSolution Quick.CMS Through 6.8.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory