An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameters date_from, date_to, and id_product allows a remote attacker to retrieve the contents of an entire database.
id: CVE-2023-36284
info:
name: QloApps 1.6.0 - SQL Injection
author: ritikchaddha
severity: h
...