CVE-2025-54542 MEDIUM

CVE-2025-54542: Sending Password in GET Request

Vendor Opensolution
Product QuickCMS
Weakness CWE-598
Published August 28, 2025
Last update August 28, 2025

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

Key dates

02Disclosure timeline

August 28, 2025 CVE published
August 28, 2025 Record updated