CVE-2024-58308
CRITICALQuick.CMS 6.7 - Unauthenticated SQL Injection via Login Form
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-58308. PoCs published by H4X.Forensics.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Quick.CMS 6.7. The payload ' or '1'='1' bypasses the login mechanism by manipulating the SQL query.
Description
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.
Exploits (1)
This exploit demonstrates an SQL injection authentication bypass in Quick.CMS 6.7. The payload ' or '1'='1' bypasses the login mechanism by manipulating the SQL query.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H