Webkul QloApps 在将上传的文件移动到公开可访问目录之前,未对文件扩展名或 MIME 类型进行适当的验证。具有管理员权限的远程攻击者可以利用此漏洞上传可执行文件,从而引发远程代码执行。该问题已在版本 153ec1c 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75497 | 7.2 HIGH | Webkul QloApps SQL injection |
| CVE-2026-75498 | 7.2 HIGH | Webkul QloApps SQL injection |
No comments yet