OpenSolution QuickCMS 6.8 contains hardcoded admin credentials in plaintext config files…
OpenSolution QuickCMS 6.8 contains hardcoded admin credentials in plaintext config files and stored XSS in language editor, enabling privilege escalation and code injection.
CERT Polska coordinated disclosure of two vulnerabilities in OpenSolution QuickCMS version 6.8. CVE-2025-9982 involves hardcoded administrator credentials stored in plaintext within configuration files, allowing attackers with filesystem or source code access to retrieve authentication details and escalate privileges. CVE-2025-10018 is a stored cross-site scripting vulnerability in the language editor functionality that permits authenticated administrators to inject arbitrary HTML and JavaScript, which executes on every page despite default restrictions on JavaScript insertion.
The vendor was notified early in the disclosure process but did not respond with vulnerability details or clarification on the affected version range. Testing confirmed version 6.8 as vulnerable; other versions remain untested and may also be affected. Both vulnerabilities require some level of existing access—filesystem access for credential theft, admin privileges for XSS exploitation—but represent significant security weaknesses in the CMS platform.
Organizations running QuickCMS should assess their exposure, particularly if untrusted users have any level of system access or if administrative accounts may be compromised. The lack of vendor response raises concerns about patch availability and ongoing support for affected installations.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2025/11/CVE-2025-9982
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free