Vulnerability Description
A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access sensitive files outside the intended template directory, potentially exposing system configuration, PHP source code, or other sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Q-Cms | Qcms | 6.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/xiaoyangsec/cveExploitThird Party Advisory
- https://github.com/xiaoyangsec/cve/blob/main/README.mdExploitThird Party Advisory
FAQ
What is CVE-2025-50233?
CVE-2025-50233 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manip...
How severe is CVE-2025-50233?
CVE-2025-50233 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50233?
Check the references section above for vendor advisories and patch information. Affected products include: Q-Cms Qcms.