OpenSolution QuickCMS
cpe:2.3:a:opensolution:quick_cms:*:*:*:*:*:*:*
- 6.8
A blind SQL injection vulnerability exists in OpenSolution QuickCMS version 6.8. This issue arises from improper input sanitization of data provided by high-privileged users in the 'aFilesDelete' function, allowing for blind SQL injection attacks. While the vendor was notified about this vulnerability, they did not respond with details regarding the vulnerable version range. Only version 6.8 has been tested and confirmed as vulnerable, leaving the status of other versions uncertain.
Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information without being able to see the results of their actions directly.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.