GHSA-pjph-5h96-886cHighCVSS 6.5

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin...

Published
September 20, 2026
Last Modified
September 20, 2026

🔗 CVE IDs covered (1)

📋 Description

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.

🔗 References (8)