Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-26058


Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.


Published

2025-02-18T18:15:35.653

Last Modified

2025-07-09T14:54:04.937

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.2 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-598

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webkul qloapps 1.6.1 Yes

References