quickapps/cms
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting quickapps/cmspage 1 of 1
- CVE-2017-1000495MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.0.02018-01-03
vulnerable: 2.0.0-beta1, 2.0.0-beta2
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
- CVE-2018-17102HIGHCVSS 8.8EG 8.82018-09-16
vulnerable: 2.0.0-beta1, 2.0.0-beta2
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.
- CVE-2018-9108HIGHCVSS 8.8EG 8.82018-03-28
vulnerable: 2.0.0-beta2
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.
Check whether quickapps/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for quickapps/cms CVEs against the assets you own.
Start Free Scan →