Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Quark Drive < 0.8.5 Mass Assignment via POST /update
Vulnerability Description
Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-915
Vulnerability Title
quark-auto-save 安全漏洞
Vulnerability Description
quark-auto-save是Cp0204个人开发者的一个夸克网盘自动转存与签到管理工具。 quark-auto-save 0.8.5之前版本存在安全漏洞,该漏洞源于POST /update端点存在批量赋值漏洞,可能导致经过身份验证的攻击者通过发布任意webui对象覆盖管理员凭据,导致锁定合法管理员并持久访问所有配置任务、云令牌和通知服务。
CVSS Information
N/A
Vulnerability Type
N/A