Metrics
Affected Vendors & Products
Mon, 22 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Webkul
Webkul qloapps |
|
Vendors & Products |
Webkul
Webkul qloapps |
Sun, 21 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We are already aware about this vulnerability and our Internal team are already working on this issue. (...) We'll implement the fix for this vulnerability in our next major release." | |
Title | Webkul QloApps CSRF Token authorization | |
Weaknesses | CWE-285 CWE-639 |
|
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-21T01:02:06.341Z
Updated: 2025-09-22T14:36:40.498Z
Reserved: 2025-09-20T07:00:55.215Z
Link: CVE-2025-10759

Updated: 2025-09-22T14:36:33.160Z

Status : Awaiting Analysis
Published: 2025-09-21T01:15:49.020
Modified: 2025-09-22T21:23:01.543
Link: CVE-2025-10759

No data.