Sensitive Credentials Exposure in QuickCMS by OpenSolution
CVE-2025-9982

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 November 2025

What is CVE-2025-9982?

A critical vulnerability in QuickCMS version 6.8 allows for the hardcoded exposure of sensitive admin credentials. These credentials, stored in plaintext within a configuration file, can be accessed by attackers with the appropriate access to either the source code or the file system. This flaw poses a significant risk as it can lead to privilege escalation, enabling unauthorized access to administrative functionalities. While only version 6.8 has been confirmed as vulnerable, the potential for similar issues in other versions remains untested. Immediate attention is advised for users running this software.

Affected Version(s)

QuickCMS 6.8

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.
CVE-2025-9982 : Sensitive Credentials Exposure in QuickCMS by OpenSolution