PT-2026-49188 · Quick.Cms · Quick.Cms
CVSS v4.0
7.5
High
| Vector | AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Quick.CMS versions prior to 6.8
Description
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads can trigger dangerous magic methods, such as
wakeup() and destruct(), and leverage gadget chains to achieve arbitrary code execution. Exploitation occurs automatically when an administrator accesses the admin panel.Recommendations
Update to version 6.8 or later to ensure communication is limited to HTTPS.
Fix
RCE
Deserialization of Untrusted Data
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quick.Cms