CVE-2025-26058

MEDIUM

Webkul QloApps <1.6.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.

Scores

CVSS v3 4.2
EPSS 0.0003
EPSS Percentile 9.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-598
Status published
Products (1)
webkul/qloapps 1.6.1
Published Feb 18, 2025
Tracked Since Feb 18, 2026