CVE-2023-36235: Medium severity qloapps vulnerability
Published Jan 17, 2024
·Updated
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the idorder parameter.
Affected Software
1 affected component
Webkul QloApps<1.6.0
Remediation
Patch Available
Event History
Jan 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36235?
CVE-2023-36235 has a medium severity rating due to the potential for sensitive information disclosure.
2
How do I fix CVE-2023-36235?
To resolve CVE-2023-36235, users should upgrade to Webkul QloApps version 1.6.0 or later.
3
What type of sensitive information can be exposed by CVE-2023-36235?
CVE-2023-36235 allows an attacker to access sensitive information associated with the id_order parameter.
4
Which versions of QloApps are affected by CVE-2023-36235?
CVE-2023-36235 affects all versions of QloApps prior to 1.6.0.
5
Is CVE-2023-36235 a zero-day vulnerability?
CVE-2023-36235 is not classified as a zero-day vulnerability since it has been publicly disclosed and a fix is available.