Reflected XSS Vulnerability in QuickCMS.EXT by OpenSolution
CVE-2025-54175
4.6MEDIUM
What is CVE-2025-54175?
QuickCMS.EXT, developed by OpenSolution, is susceptible to a reflected XSS vulnerability within the thumbnail viewer functionality, specifically in the sFileName parameter. This vulnerability allows attackers to craft malicious URLs that exploit the weakness, enabling arbitrary JavaScript to execute in the victim's browser upon following the link. Although version 6.8 has been confirmed as vulnerable, other versions may also be affected, as they have not undergone testing. Users are urged to exercise caution and consider immediate protective measures.
Affected Version(s)
Quick.CMS.EXT 6.8
