CVE-2026-63301
OpenSolution Quick.CMS
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forger...
- CVSS
- 7
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.28