CVE-2025-26058
MEDIUM 4.2EPSS 0.2%
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
- CVSS v3.1
- 4.2 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L - EPSS
- 0.21% chance of exploitation in the next 30 days, 12th percentile
- Published
- 2025-02-18
- Updated
- 2025-02-19
Proof-of-concept exploits (1)
- mano257200/QloApps-VUL0★ · 2025-09-14