Path Traversal Vulnerability in Quick.CMS by Open Solution
CVE-2026-63303
5.1MEDIUM
What is CVE-2026-63303?
A Path Traversal vulnerability exists in Quick.CMS, allowing an authenticated attacker with admin privileges to manipulate HTTP requests. By exploiting this flaw, an attacker can craft a URI containing dot-dot-slash (../) sequences to access files located outside the intended webroot directory. This means sensitive files in sibling directories may be exposed if proper security measures are not implemented.
Affected Version(s)
Quick.CMS 0 <= 6.8.0
