GHSA-2q2p-6wq8-66hpHighCVSS 7.2

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types...

Published
August 25, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.

🔗 References (5)