Quick.CMS admin panel has SQL injection flaw
A blind SQL injection vulnerability in OpenSolution Quick.CMS 6.8's admin panel lets high-privileged users bypass validation and potentially destroy the database.
CERT Polska coordinated disclosure of CVE-2026-33385, a blind SQL injection vulnerability affecting OpenSolution Quick.CMS, discovered in version 6.8 though other versions may be affected. The flaw stems from improper neutralization of input across multiple administration panel fields, allowing an authenticated high-privileged user to inject SQL and bypass front-end validation controls, with potential for database destruction.
Notably, the vendor has declined to remediate the issue, arguing that the administration panel is already designed for users with significant trust and modification capabilities, making the SQL injection a secondary concern within the existing trust model. This is a low-severity disclosure from an exploitation standpoint since it requires existing high-privilege administrative access, but organizations running Quick.CMS should be aware that no patch is forthcoming and should apply compensating controls around admin account access.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-33385
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free