PT-2025-50760 · Quick.Cms · Quick.Cms

·

CVE-2024-58308

·

Published

2025-12-11

·

Updated

2025-12-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quick.CMS version 6.7
Description The software contains a SQL injection flaw that allows unauthenticated attackers to bypass login authentication. Attackers can manipulate the login form with SQL payloads, such as ' or '1'='1, to gain unauthorized administrative access. The vulnerable component is the login form. The API endpoint involved is the login form. The vulnerable parameter is the username field.
Recommendations Apply a fix to sanitize user input in the login form to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58308

Affected Products

Quick.Cms