vendor:
Quick.CMS
by:
mari0x00
7.2
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Quick.CMS
Affected Version From: <= 6.7
Affected Version To: <= 6.7
Patch Exists: YES
Related CWE: CVE-2020-35754
CPE: a:opensolution:quick.cms:6.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Quick.CMS 6.7 – Remote Code Execution (Authenticated)
Quick.CMS 6.7 is vulnerable to an authenticated Remote Code Execution vulnerability. An attacker can exploit this vulnerability by sending a specially crafted payload to the vulnerable application. This payload will execute arbitrary code on the server, allowing the attacker to gain access to the system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Quick.CMS 6.7.