OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
| Software | From | Fixed in |
|---|---|---|
| opensolution / quick.cms | - | 6.7 |
| opensolution / quick.cart | - | 6.7 |