{"id":"CVE-2018-17102","details":"An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.","aliases":["GHSA-3p9v-xp6w-wcmc"],"modified":"2026-07-08T17:16:41.591356Z","published":"2018-09-16T21:29:01.893Z","references":[{"type":"EVIDENCE","url":"https://github.com/quickapps/cms/issues/187"},{"type":"EVIDENCE","url":"https://github.com/quickapps/cms/issues/199"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/quickapps/cms","events":[{"introduced":"0"},{"last_affected":"a2cc3dfc51e6fa9cf2209c1fe64697e89512d365"},{"introduced":"52b9ef1f7f782d709d616c168d50f0cf0914dc51"},{"last_affected":"9c3200a8cbabb8d8b1b6972d7e51a6067b60395f"}],"database_specific":{"cpe":["cpe:2.3:a:quickappscms:quickapps_cms:*:*:*:*:*:*:*:*","cpe:2.3:a:quickappscms:quickapps_cms:2.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:quickappscms:quickapps_cms:2.0.0:beta2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.1.2"},{"introduced":"2.0.0-beta1"},{"last_affected":"2.0.0-beta1"},{"introduced":"2.0.0-beta2"},{"last_affected":"2.0.0-beta2"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.0.0-beta1","2.0.0-beta2","1.1.2","1.1.1","1.1-RC2","1.1-RC1","1.1-beta","1.0","1.0-RC3","1.0-RC2","1.0-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-17102.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}