Local File Inclusion Vulnerability in Quick.CMS by OpenSolution
CVE-2026-63302
5.1MEDIUM
What is CVE-2026-63302?
Quick.CMS contains a vulnerability in its admin.php endpoint that allows Local File Inclusion (LFI) through the manipulated 'p' parameter. Authenticated users with admin access can exploit this weakness by sending a crafted HTTP request, enabling them to include arbitrary files from the server's directory structure. This exploitation can lead to the disclosure of sensitive information, including the server's directory structure and absolute file paths, potentially compromising the overall security of the system.
Affected Version(s)
Quick.CMS 0 <= 6.8.0
