PT-2025-46953 · Quick.Cms · Quick.Cms

Karol Czubernat

·

Published

2025-11-14

·

Updated

2025-11-14

·

CVE-2025-9982

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QuickCMS version 6.8
Description A flaw exists where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-9982

Affected Products

Quick.Cms