OpenSolution QuickCMS Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability exists in OpenSolution QuickCMS version 6.8. This issue arises from improper input sanitization of data provided by high-privileged users in the 'aFilesDelete' function, allowing for blind SQL injection attacks. While the vendor was notified about this vulnerability, they did not respond with details regarding the vulnerable version range. Only version 6.8 has been tested and confirmed as vulnerable, leaving the status of other versions uncertain.

Impact

Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information without being able to see the results of their actions directly.

Added: Dec 2, 2025, 1:18 PM
Updated: Dec 2, 2025, 5:48 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.