{"id":"CVE-2024-58308","details":"Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.","modified":"2026-03-15T22:18:34.836464Z","published":"2025-12-11T22:15:52.340Z","references":[{"type":"WEB","url":"https://www.opensolution.org"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/quickcms-sql-injection-authentication-bypass-via-admin-login"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/51910"},{"type":"EVIDENCE","url":"https://opensolution.org/download/home.html?sFile=Quick.Cms_v6.7-en.zip"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58308.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"6.7"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}