CVE-2026-75496

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 17:18

Updated : 2026-08-26 16:52


NVD link : CVE-2026-75496

Mitre link : CVE-2026-75496

CVE.ORG link : CVE-2026-75496


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type