GHSA-pjph-5h96-886cHighCVSS 6.5
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin...
🔗 CVE IDs covered (1)
📋 Description
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93988
- https://github.com/Qloapps/QloApps/pull/1719
- https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715
- https://github.com/Qloapps/QloApps
- https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051
- https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal
- https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml
- https://github.com/advisories/GHSA-pjph-5h96-886c