漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of Service in Quick.CMS
Vulnerability Description
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
服务端安全的客户端实施
Vulnerability Title
OpenSolution Quick.CMS 处理逻辑错误漏洞
Vulnerability Description
OpenSolution quick.cms是OpenSolution组织开源的一个内容管理系统。 OpenSolution Quick.CMS 6.8.0及之前版本存在处理逻辑错误漏洞,该漏洞源于语言删除API端点未强制执行服务器端授权检查,导致认证管理员可绕过UI限制直接请求删除主语言,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A