Webkul QloApps 在数据库查询前未对请求参数进行验证。具备管理权限的远程攻击者可以向 文件中的 参数发送构造好的 SQL 查询。该漏洞已在提交 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75497 | 7.2 HIGH | Webkul QloApps SQL injection |
| CVE-2026-75496 | 7.2 HIGH | Webkul QloApps improper file upload validation |
No comments yet