Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 17:18
Updated : 2026-08-26 16:52
NVD link : CVE-2026-75496
Mitre link : CVE-2026-75496
CVE.ORG link : CVE-2026-75496
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
