CVE-2026-75497

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 17:18

Updated : 2026-08-26 16:52


NVD link : CVE-2026-75497

Mitre link : CVE-2026-75497

CVE.ORG link : CVE-2026-75497


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')