A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:opensolution:quick.cms:6.8:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Sat, 15 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensolution
Opensolution quick.cms |
|
| Vendors & Products |
Opensolution
Opensolution quick.cms |
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |
| Title | Hard-coded admin credentials in Quick.CMS | |
| Weaknesses | CWE-256 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-11-14T13:22:16.515Z
Updated: 2025-11-14T15:45:56.708Z
Reserved: 2025-09-04T13:20:17.285Z
Link: CVE-2025-9982
Updated: 2025-11-14T15:45:52.405Z
Status : Analyzed
Published: 2025-11-14T14:15:47.113
Modified: 2025-11-17T19:28:12.123
Link: CVE-2025-9982
No data.