Cp0204/quark-auto-save

Cp0204/quark-auto-save

Releases83
Frequency1 week 2 days
Last Release
Stars2.85K
夸克网盘签到、自动转存、命名整理、发推送提醒和刷新媒体库一条龙

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update endpoint, which are persisted to disk and executed in the browsers of all authenticated users accessing the System Configuration tab, allowing session cookie exfiltration and arbitrary authenticated actions.

8.8 HIGH

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services.