Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93988— QloApps through 1.7.0 Arbitrary File Read via getEmailHTML

Quick assessment

Affected
webkul qloapps
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

QloApps 1.7.0 及之前版本中,admin/ajax.php 的 getEmailHTML 接口存在路径遍历漏洞,使得已认证的后台用户能够读取任意文件。攻击者可通过在 email 参数中提供相对路径序列来绕过目录限制,从而访问敏感文件,包括数据库凭据和配置数据。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1195 · Supply Chain Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93988

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
Source: CVE Program / CVE List V5
Vulnerability Description
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
webkul qloapps 0 ~ 1.7.0 -

II. Public POCs for CVE-2026-93988

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93988

登录查看更多情报信息。

Patches & Fixes for CVE-2026-93988 (2)

Vendor Advisories for CVE-2026-93988 (1)

Exploits & Public PoCs for CVE-2026-93988 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93988

No comments yet


Leave a comment