for a victim and later hijack the authenticated session.
This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensolution
Opensolution quick.cms |
|
| Vendors & Products |
Opensolution
Opensolution quick.cms |
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable. | |
| Title | Session Fixation in QuickCMS | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-29T17:31:52.144Z
Reserved: 2026-03-19T10:45:47.735Z
Link: CVE-2026-33384
Updated: 2026-05-29T17:31:49.345Z
Status : Deferred
Published: 2026-05-29T16:16:25.417
Modified: 2026-05-29T16:29:11.350
Link: CVE-2026-33384
No data.
OpenCVE Enrichment
Updated: 2026-05-29T17:45:04Z