OpenSolution QuickCMS Session Fixation Vulnerability Allowing Session Hijacking

Vulnerability

A session fixation vulnerability has been identified in OpenSolution QuickCMS versions prior to 6.8. This issue allows an attacker to set a user's session identifier before authentication, with the session ID remaining unchanged after authentication. As a result, an attacker can hijack an authenticated session by fixing a session ID for a victim.

Impact

Exploitation of this vulnerability allows for session hijacking, where an attacker can take over an authenticated user's session.

Remediation

Users can upgrade to QuickCMS version 6.8, released on May 15, 2026, to address this vulnerability.

Added: May 29, 2026, 4:30 PM
Updated: May 29, 2026, 4:30 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.3
exploitability
6.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.