CVE-2025-12465

HIGH

QuickCMS 6.8 - Authenticated Blind SQL Injection via aFilesDelete

Title source: llm
STIX 2.1

Description

A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

References (1)

Core 1
Core References
Various Sources third-party-advisory
https://cert.pl/posts/2025/12/CVE-2025-12465/

Scores

CVSS v4 8.6
EPSS 0.0023
EPSS Percentile 13.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
OpenSolution/QuickCMS 6.8
Published Dec 02, 2025
Tracked Since Feb 18, 2026