Vulnerability Details CVE-2024-58308
Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 70.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-58308
-
cpe:2.3:a:opensolution:quick_cms:6.7