CVE-2020-35754: Opensolution Quick.cart
High severity, CVSS 7.2. EPSS: 10.5% chance of exploitation in the next 30 days.
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
Affected products
- Opensolution Quick.cart: before 6.7 (fixed in 6.7)
- Opensolution Quick.cms: before 6.7 (fixed in 6.7)
Published 2021-01-28. Last modified 2026-06-17.