Local File Inclusion Vulnerability in Quick.CMS by OpenSolution
CVE-2026-63302

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-63302?

Quick.CMS contains a vulnerability in its admin.php endpoint that allows Local File Inclusion (LFI) through the manipulated 'p' parameter. Authenticated users with admin access can exploit this weakness by sending a crafted HTTP request, enabling them to include arbitrary files from the server's directory structure. This exploitation can lead to the disclosure of sensitive information, including the server's directory structure and absolute file paths, potentially compromising the overall security of the system.

Affected Version(s)

Quick.CMS 0 <= 6.8.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.