CVE-2024-58308
CRITICALOpensolution Quick Cms - SQL Injection
Title source: ruleDescription
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (2)
opensolution/Quick.CMS
6.7
opensolution/quick_cms
6.7
Published
Dec 11, 2025
Tracked Since
Feb 18, 2026