Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63302

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/07/2026
Última modificación:
28/07/2026

Descripción

*** Pendiente de traducción *** Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application&amp;#39;s directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server&amp;#39;s directory structure and absolute file paths (path disclosure).<br /> <br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

Referencias a soluciones, herramientas e información