Denial of Service Vulnerability in Quick.CMS by OpenSolution
CVE-2026-63301
7HIGH
What is CVE-2026-63301?
In Quick.CMS, the administrative user interface prevents the deletion of the primary language through a UI restriction, but an underlying API endpoint lacks proper server-side authorization. This allows an authenticated administrator to bypass the UI restriction using direct HTTP requests to delete the primary language, resulting in a Denial of Service (DoS) condition for the application. Furthermore, when paired with a separate Cross-Site Request Forgery (CSRF) vulnerability, an unauthenticated remote attacker could exploit this flaw by crafting a malicious link that triggers the DoS condition simply through interaction by an authenticated administrator.
Affected Version(s)
Quick.CMS 0 <= 6.8.0
