Vulnerability Description
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensolution | Quick Cms | 6.7 |
Related Weaknesses (CWE)
References
- https://opensolution.org/download/home.html?sFile=Quick.Cms_v6.7-en.zipExploit
- https://www.exploit-db.com/exploits/51910Exploit
- https://www.opensolution.orgProduct
- https://www.vulncheck.com/advisories/quickcms-sql-injection-authentication-bypasThird Party Advisory
FAQ
What is CVE-2024-58308?
CVE-2024-58308 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads lik...
How severe is CVE-2024-58308?
CVE-2024-58308 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-58308?
Check the references section above for vendor advisories and patch information. Affected products include: Opensolution Quick Cms.