CVE-2023-36288: XSS
Published Jun 23, 2023
·Updated
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Affected Software
1 affected component
Webkul QloApps=1.6.0
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-36288?
CVE-2023-36288 is an unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0.
2
What is the severity of CVE-2023-36288?
CVE-2023-36288 has a severity level of medium, with a severity value of 5.4.
3
How can an attacker exploit CVE-2023-36288?
An attacker can exploit CVE-2023-36288 by obtaining a user's session cookie and impersonating that user via the GET configure parameter.
4
Which software version is affected by CVE-2023-36288?
CVE-2023-36288 affects Webkul QloApps version 1.6.0.
5
How can I fix CVE-2023-36288?
To fix CVE-2023-36288, update Webkul QloApps to a version that includes the necessary security patches.