CVE-2026-63303: CWE-23 Relative path traversal in OpenSolution Quick.CMS
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
AI Analysis
Technical Summary
This vulnerability involves improper handling of dot-dot-slash (../) sequences in the URI path component of HTTP requests in Quick.CMS. An authenticated attacker with administrative privileges can craft requests containing ../ sequences to access files located in directories adjacent to the webroot. The server fails to normalize these sequences before resolving file paths, enabling relative path traversal. The vendor has assessed the risk as low and decided that a patch is not required.
Potential Impact
An attacker with admin privileges can read arbitrary files outside the webroot directory, potentially exposing sensitive information stored on the server. However, exploitation requires authenticated admin access, limiting the scope of impact. There are no known exploits in the wild.
Mitigation Recommendations
The vendor has determined that a fix is not necessary due to the very low likelihood of exploitation. No official patch or remediation is currently available. Users should ensure that admin credentials are well protected to reduce risk.
CVE-2026-63303: CWE-23 Relative path traversal in OpenSolution Quick.CMS
Description
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
CVSS v4.0
Score 5.1medium
Affected software
OpenSolution
Quick.CMS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper handling of dot-dot-slash (../) sequences in the URI path component of HTTP requests in Quick.CMS. An authenticated attacker with administrative privileges can craft requests containing ../ sequences to access files located in directories adjacent to the webroot. The server fails to normalize these sequences before resolving file paths, enabling relative path traversal. The vendor has assessed the risk as low and decided that a patch is not required.
Potential Impact
An attacker with admin privileges can read arbitrary files outside the webroot directory, potentially exposing sensitive information stored on the server. However, exploitation requires authenticated admin access, limiting the scope of impact. There are no known exploits in the wild.
Mitigation Recommendations
The vendor has determined that a fix is not necessary due to the very low likelihood of exploitation. No official patch or remediation is currently available. Users should ensure that admin credentials are well protected to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-07-16T10:27:23.339Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a688d829c2644c7f87ffd2f
Added to database: 07/28/2026, 11:07:46 UTC
Last enriched: 07/30/2026, 00:07:57 UTC
Last updated: 09/11/2026, 22:06:34 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.