Beveiligingsadvies

CVE-2026-45228

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-13 19:54:40
Laatst bijgewerkt 2026-07-14 20:01:20
Toegewezen door VulnCheck
CVSS-score 5.4
Status PUBLISHED

Beschrijving

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update endpoint, which are persisted to disk and executed in the browsers of all authenticated users accessing the System Configuration tab, allowing session cookie exfiltration and arbitrary authenticated actions.