ZeroHour

CVE-2025-26058

PoC
CVSS 3.1
4.2 medium
EPSS
<1%p12
Published
()
Modified
Description

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.

Vendors
webkul
Products
qloapps
Weakness
CWE-598
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.