CVE-2020-35754
CVE-2020-35754
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/161189/Quick.CMS-6.7-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/49494unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/161189/Quick.CMS-6.7-Remote-Code-Execution.htmlhttps://opensolution.org/cms-system-quick-cms.htmlhttps://opensolution.org/security-fix-for-cart-and-cms%21-en-1136.htmlhttps://secator.pl/index.php/2021/01/28/cve-2020-35754-authenticated-rce-in-quick-cms-and-quick-cart/