Opensolution

Quick.Cms

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 28.08.2025 11:15:30
  • Zuletzt bearbeitet 08.09.2025 17:06:51

QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was n...

  • EPSS 0.02%
  • Veröffentlicht 20.08.2025 12:53:09
  • Zuletzt bearbeitet 08.09.2025 17:08:58

QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content de...

  • EPSS 0.02%
  • Veröffentlicht 20.08.2025 12:52:47
  • Zuletzt bearbeitet 08.09.2025 17:10:23

QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin us...

Exploit
  • EPSS 14.46%
  • Veröffentlicht 28.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:28:00

OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.07.2012 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 01.12.2009 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a p-delete action to admin.php, and...