Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webkul qloapps vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-36235
An issue in webkul qloapps before v1.6.0 allows an malicious user to obtain sensitive information via the id_order parameter.
Webkul Qloapps
NA
CVE-2023-30256
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote malicious user to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
Webkul Qloapps 1.5.2
1 Github repository
NA
CVE-2023-36284
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote malicious user to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire data...
Webkul Qloapps 1.6.0
NA
CVE-2023-36287
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via POST controller parameter.
Webkul Qloapps 1.6.0
NA
CVE-2023-36288
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Webkul Qloapps 1.6.0
NA
CVE-2023-36289
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
Webkul Qloapps 1.6.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4654
CVE-2023-49606
encryption
NULL pointer dereference
CVE-2024-4439
CVE-2024-4649
race condition
CVE-2024-27202
CVE-2024-34566
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started