Back to overview

CVE-2026-63301

HIGH
7.0
CVSS 4.0
Description
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

Metadata

CVE ID
CVE-2026-63301
State
PUBLISHED
Assigner
CERT-PL
Reserved
2026-07-16 10:27 UTC
Published
2026-07-28 10:42 UTC
Last updated
2026-07-28 12:29 UTC
Primary CWE
CWE-602
CWE-602 Client-Side Enforcement of Server-Side Security
Vendor / Product
OpenSolution / Quick.CMS
Sources
cve.org  ·  NVD

Severity & Metrics

7.0 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
OpenSolution Quick.CMS 0 ≤ 6.8.0
Weakness (CWE)
CWESourceDescription
CWE-602 cna CWE-602 Client-Side Enforcement of Server-Side Security
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.0 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Back to overview