PT-2026-44893 · Opensolution · Quick.Cms
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
QuickCMS versions prior to 6.8 patch 15.05.2026
Description
QuickCMS allows a user session identifier to be established before authentication, and this value remains unchanged after the user authenticates. This behavior enables session fixation, where an attacker can predetermine a session ID for a victim and subsequently hijack the session once the victim has authenticated.
Recommendations
Apply the patch published on 15.05.2026 for version 6.8.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick.Cms