Blind SQL Injection Vulnerability in QuickCMS by an Unknown Vendor
CVE-2025-12465
8.6HIGH
What is CVE-2025-12465?
A Blind SQL injection vulnerability exists in QuickCMS, specifically due to inadequate input handling by high-privileged users in the aFilesDelete function. This flaw allows adversaries to execute unauthorized SQL commands without direct feedback, which can lead to unauthorized access to sensitive data. While version 6.8 has been confirmed as vulnerable, other versions remain untested and could potentially be at risk. Prompt action is needed to address these vulnerabilities to safeguard against exploitation.
Affected Version(s)
QuickCMS 6.8
