quickapps/cms
QuickAppsCMS, open source content management system for PHP
Activity
- Latest release
- 11y ago
- Total releases
- 2
- Cadence
- ~37 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- GPL-3.0
- First release
- Apr 20, 2015
| Version | Released | |
|---|---|---|
2.0.0-beta2
pre
3 CVEs
CVE-2017-1000495
GHSA-825g-f3g2-6vxf
May 14, 2022
QuickApps CMS Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account Affected versions
2.0.0-beta1
2.0.0-beta2
Fixed in
2.0.0
References Updated Apr 23, 2024 · Source: OSV.dev
CVE-2018-9108
GHSA-62g2-8p9f-ghjp
May 14, 2022
QuickAppsCMS Cross-Site Request Forgery (CSRF)
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
CSRF in Affected versions
2.0.0-beta2
References Updated Apr 23, 2024 · Source: OSV.dev
CVE-2018-17102
GHSA-3p9v-xp6w-wcmc
May 14, 2022
QuickAppsCMS Cross-Site Request Forgery (CSRF)
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI. Affected versions
2.0.0-beta1
2.0.0-beta2
References Updated Apr 23, 2024 · Source: OSV.dev | ||
2.0.0-beta1
pre
2 CVEs
CVE-2017-1000495
GHSA-825g-f3g2-6vxf
May 14, 2022
QuickApps CMS Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account Affected versions
2.0.0-beta1
2.0.0-beta2
Fixed in
2.0.0
References Updated Apr 23, 2024 · Source: OSV.dev
CVE-2018-17102
GHSA-3p9v-xp6w-wcmc
May 14, 2022
QuickAppsCMS Cross-Site Request Forgery (CSRF)
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI. Affected versions
2.0.0-beta1
2.0.0-beta2
References Updated Apr 23, 2024 · Source: OSV.dev |