Directory Traversal Vulnerability in QCMS Backend Template Editor
CVE-2025-50233
6.5MEDIUM
What is CVE-2025-50233?
A vulnerability in QCMS version 6.0.5 allows authenticated users to exploit insufficient validation of the 'Name' parameter in the backend template editor. By manipulating this parameter, attackers can execute directory traversal attacks, granting them unauthorized access to sensitive files outside the designated template directory. This could lead to the exposure of critical system configuration, PHP source code, and other confidential data, potentially jeopardizing the integrity and security of the entire system.
