for a victim and later hijack the authenticated session.
This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensolution
Opensolution quick.cms |
|
| Vendors & Products |
Opensolution
Opensolution quick.cms |
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable. | |
| Title | Session Fixation in QuickCMS | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-29T17:31:52.144Z
Reserved: 2026-03-19T10:45:47.735Z
Link: CVE-2026-33384
Updated: 2026-05-29T17:31:49.345Z
Status : Deferred
Published: 2026-05-29T16:16:25.417
Modified: 2026-05-29T16:29:11.350
Link: CVE-2026-33384
No data.
OpenCVE Enrichment
Updated: 2026-05-29T17:45:04Z