Webkul QloApps 在将请求参数传递至数据库查询前未对其进行验证。具备管理员权限的远程已认证攻击者可以向 文件中的 参数注入构造好的 SQL 查询语句。该漏洞已在提交 123c97c 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75496 | 7.2 HIGH | Webkul QloApps improper file upload validation |
| CVE-2026-75498 | 7.2 HIGH | Webkul QloApps SQL injection |
No comments yet