Blind SQL Injection Vulnerability in Quick.CMS by OpenSolution
CVE-2026-33385

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-33385?

A Blind SQL injection vulnerability has been identified in Quick.CMS, allowing high-privileged users to exploit improperly neutralized input fields in the administration panel. This flaw could result in bypassing front-end validation controls, enabling unauthorized access to the database and potential data destruction. Despite the severity of this issue, the vendor has indicated that no remediation is necessary, considering the application's trust model.

Affected Version(s)

Quick.CMS 6.8

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Lipiński
.