Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/mano257200/QloApps-VUL |
![]() ![]() |
History
Wed, 09 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Webkul
Webkul qloapps |
|
CPEs | cpe:2.3:a:webkul:qloapps:1.6.1:*:*:*:*:*:*:* | |
Vendors & Products |
Webkul
Webkul qloapps |
Wed, 19 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-598 | |
Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-19T20:32:11.827Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26058

Updated: 2025-02-19T20:32:05.577Z

Status : Analyzed
Published: 2025-02-18T18:15:35.653
Modified: 2025-07-09T14:54:04.937
Link: CVE-2025-26058

No data.