CyberRota Analysis
AI-GeneratedWebkul QloApps is vulnerable due to inadequate validation of uploaded file extensions and MIME types, allowing authenticated attackers with administrative privileges to upload malicious executable files to a publicly accessible directory. This flaw can lead to remote code execution, posing a significant risk to the integrity and security of the application. Organizations using QloApps should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.