OpenSolution QuickCMS
cpe:2.3:a:opensolution:quick.cms:*:*:*:*:*:*:*, +1 more
- <= 6.8
A session fixation vulnerability has been identified in OpenSolution QuickCMS versions prior to 6.8. This issue allows an attacker to set a user's session identifier before authentication, with the session ID remaining unchanged after authentication. As a result, an attacker can hijack an authenticated session by fixing a session ID for a victim.
Exploitation of this vulnerability allows for session hijacking, where an attacker can take over an authenticated user's session.
Users can upgrade to QuickCMS version 6.8, released on May 15, 2026, to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.