Cross-Site Request Forgery Vulnerability in QuickCMS by OpenSolution
CVE-2025-54541

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 August 2025

What is CVE-2025-54541?

The QuickCMS content management system is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that affects its page deletion functionality. This flaw allows an attacker to generate a specially crafted website that, when accessed by an administrator of the system, triggers an automatic POST request to delete an article without the admin's consent. Although OpenSolution was made aware of this vulnerability, they have not disclosed detailed information regarding the vulnerable version range. So far, only QuickCMS version 6.8 has been confirmed to be vulnerable, raising concerns that other versions may also be at risk.

Affected Version(s)

QuickCMS 6.8

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.
CVE-2025-54541 : Cross-Site Request Forgery Vulnerability in QuickCMS by OpenSolution