Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2025-1155

Disclosure Date: February 10, 2025 (last updated February 11, 2025)
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term.
0
Attacker Value
Unknown

CVE-2025-1074

Disclosure Date: February 06, 2025 (last updated February 07, 2025)
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. They are aware about it and are working on resolving it.
Attacker Value
Unknown

CVE-2024-40318

Disclosure Date: July 25, 2024 (last updated August 27, 2024)
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
Attacker Value
Unknown

CVE-2023-36235

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
Attacker Value
Unknown

CVE-2023-36287

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
Attacker Value
Unknown

CVE-2023-36284

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
Attacker Value
Unknown

CVE-2023-36289

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
Attacker Value
Unknown

CVE-2023-36288

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Attacker Value
Unknown

CVE-2023-30256

Disclosure Date: May 11, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.