CVE-2025-10759: Webkul QloApps CSRF Token authorization
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We are already aware about this vulnerability and our Internal team are already working on this issue. (...) We'll implement the fix for this vulnerability in our next major release."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10759?
CVE-2025-10759 has a high severity level due to its potential for remote exploitation and authorization bypass.
How do I fix CVE-2025-10759?
To fix CVE-2025-10759, upgrade Webkul QloApps to version 1.7.1 or later where the vulnerability has been addressed.
What components are affected by CVE-2025-10759?
CVE-2025-10759 affects the CSRF Token Handler component in Webkul QloApps versions up to 1.7.0.
Can CVE-2025-10759 be exploited remotely?
Yes, CVE-2025-10759 can be exploited remotely, allowing attackers to manipulate the CSRF token for unauthorized access.
What type of vulnerability is CVE-2025-10759?
CVE-2025-10759 is classified as an authorization bypass vulnerability.