← volver
CVE-2026-45228

Quark Drive (quark-auto-save) < 0.8.5 Stored XSS via System Configuration

CVSS 5.1 MEDIUMEPSS 0.2%CWE-79
Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update endpoint, which are persisted to disk and executed in the browsers of all authenticated users accessing the System Configuration tab, allowing session cookie exfiltration and arbitrary authenticated actions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Productos afectados
Cp0204 · quark-auto-save

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →