Sensitive Credentials Exposure in QuickCMS by OpenSolution
CVE-2025-9982
6.9MEDIUM
What is CVE-2025-9982?
A critical vulnerability in QuickCMS version 6.8 allows for the hardcoded exposure of sensitive admin credentials. These credentials, stored in plaintext within a configuration file, can be accessed by attackers with the appropriate access to either the source code or the file system. This flaw poses a significant risk as it can lead to privilege escalation, enabling unauthorized access to administrative functionalities. While only version 6.8 has been confirmed as vulnerable, the potential for similar issues in other versions remains untested. Immediate attention is advised for users running this software.
Affected Version(s)
QuickCMS 6.8
