ZeroHour

CVE-2025-67325

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
Description

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

Vendors
webkul
Products
qloapps
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.