PT-2026-44894 · Opensolution · Quick.Cms
CVSS v4.0
2.3
Low
| Vector | AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
QuickCMS versions prior to 6.8 patch published on 15.05.2026
Description
An issue exists due to an insecure HTTP-based plugin-fetching mechanism. A remote attacker can execute a Man-in-the-Middle (MITM) attack—a technique where an attacker intercepts communication between two parties—by impersonating the opensolution.org server. By serving arbitrary HTML or JavaScript at the plugin list endpoint, the malicious content is automatically fetched, rendered, and executed when a user accesses the plugin page, leading to Cross-Site Scripting (XSS).
Recommendations
Apply the patch for version 6.8 published on 15.05.2026.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick.Cms