PT-2025-34050 · Quick.Cms · Quick.Cms
Kamil Szczurowski
+1
·
Published
2025-08-20
·
Updated
2025-09-08
·
CVE-2025-54172
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
QuickCMS version 6.8
QuickCMS (affected versions not specified)
Description:
QuickCMS is vulnerable to Stored Cross-Site Scripting (XSS) in the
sTitle parameter within the page editor functionality. A malicious attacker with admin privileges can inject arbitrary HTML and JavaScript into the website, which will be rendered and executed when visiting the edited page. A regular admin user is not able to inject any JavaScript scripts into the page. The vendor was notified about this issue but did not respond with details regarding vulnerable version ranges.Recommendations:
QuickCMS version 6.8: As a temporary workaround, sanitize the
sTitle input to prevent the injection of malicious HTML and JavaScript code.
QuickCMS (affected versions not specified): As a temporary workaround, sanitize the sTitle input to prevent the injection of malicious HTML and JavaScript code.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick.Cms