Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-41074. PoCs published by dillonkirsch.
AI-analyzed exploit summary This repository contains a writeup describing a CSRF vulnerability in Qloapps HotelCommerce 1.5.1, which allows an attacker to change the admin email by tricking an admin into clicking a malicious HTML document.
Description
A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
Exploits (1)
nomisec
WRITEUP
by dillonkirsch · poc
https://github.com/dillonkirsch/CVE-2021-41074
This repository contains a writeup describing a CSRF vulnerability in Qloapps HotelCommerce 1.5.1, which allows an attacker to change the admin email by tricking an admin into clicking a malicious HTML document.
Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target:
Qloapps HotelCommerce 1.5.1
No auth needed
Prerequisites:
Admin user interaction (clicking a malicious link)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Third Party Advisory
https://github.com/dillonkirsch/CVE-2021-41074
Product
https://qloapps.com/
Scores
CVSS v3
5.4
EPSS
0.0002
EPSS Percentile
6.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
webkul/qloapps
1.5.1
Published
Jan 12, 2026
Tracked Since
Feb 18, 2026