First published: Thu May 11 2023(Updated: )
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkul QloApps | =1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30256 is a Cross Site Scripting vulnerability found in Webkul QloApps v.1.5.2.
CVE-2023-30256 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
The severity of CVE-2023-30256 is medium with a score of 6.1.
To fix CVE-2023-30256, update Webkul QloApps to a version that has a patch for this vulnerability.
You can find more information about CVE-2023-30256 in the following references: [Link 1](http://packetstormsecurity.com/files/172542/Webkul-Qloapps-1.5.2-Cross-Site-Scripting.html), [Link 2](https://github.com/ahrixia/CVE-2023-30256), [Link 3](https://github.com/webkul/hotelcommerce).