Directory Traversal Vulnerability in QCMS Backend Template Editor
CVE-2025-50233

6.5MEDIUM

Key Information:

Vendor

QCMS

Status
Vendor
CVE Published:
6 August 2025

What is CVE-2025-50233?

A vulnerability in QCMS version 6.0.5 allows authenticated users to exploit insufficient validation of the 'Name' parameter in the backend template editor. By manipulating this parameter, attackers can execute directory traversal attacks, granting them unauthorized access to sensitive files outside the designated template directory. This could lead to the exposure of critical system configuration, PHP source code, and other confidential data, potentially jeopardizing the integrity and security of the entire system.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.