Denial of Service Vulnerability in Quick.CMS by OpenSolution
CVE-2026-63301

7HIGH

Key Information:

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-63301?

In Quick.CMS, the administrative user interface prevents the deletion of the primary language through a UI restriction, but an underlying API endpoint lacks proper server-side authorization. This allows an authenticated administrator to bypass the UI restriction using direct HTTP requests to delete the primary language, resulting in a Denial of Service (DoS) condition for the application. Furthermore, when paired with a separate Cross-Site Request Forgery (CSRF) vulnerability, an unauthenticated remote attacker could exploit this flaw by crafting a malicious link that triggers the DoS condition simply through interaction by an authenticated administrator.

Affected Version(s)

Quick.CMS 0 <= 6.8.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.