CVE-2025-26058

MEDIUM

Webkul QloApps <1.6.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.

References (1)

Core 1
Core References

Scores

CVSS v3 4.2
EPSS 0.0021
EPSS Percentile 10.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-598
Status published
Products (1)
webkul/qloapps 1.6.1
Published Feb 18, 2025
Tracked Since Feb 18, 2026