OpenSolution quick.cms是OpenSolution组织开源的一个内容管理系统。 OpenSolution Quick.CMS 6.8.0及之前版本存在代码注入漏洞,该漏洞源于admin.php端点通过p参数存在本地文件包含漏洞,可能导致经过身份验证的攻击者包含应用目录结构中的任意文件,从而泄露服务器目录结构和绝对文件路径。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenSolution | Quick.CMS | ≤ 6.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenSolution | Quick.CMS | 0 ~ 6.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63301 | 7.0 HIGH | Denial of Service in Quick.CMS |
| CVE-2026-41874 | 6.8 MEDIUM | Hard-coded admin credentials in Quick.Cart |
| CVE-2026-63303 | 5.1 MEDIUM | Path Traversal in Quick.CMS |
No comments yet