CVE-2023-30256: XSS
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and emailcreate parameters in the AuthController.php file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30256?
CVE-2023-30256 is a Cross Site Scripting vulnerability found in Webkul QloApps v.1.5.2.
How does CVE-2023-30256 affect Webkul QloApps?
CVE-2023-30256 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
What is the severity of CVE-2023-30256?
The severity of CVE-2023-30256 is medium with a score of 6.1.
How can I fix CVE-2023-30256?
To fix CVE-2023-30256, update Webkul QloApps to a version that has a patch for this vulnerability.
Where can I find more information about CVE-2023-30256?
You can find more information about CVE-2023-30256 in the following references: [Link 1](http://packetstormsecurity.com/files/172542/Webkul-Qloapps-1.5.2-Cross-Site-Scripting.html), [Link 2](https://github.com/ahrixia/CVE-2023-30256), [Link 3](https://github.com/webkul/hotelcommerce).