CVE-2025-1155: Webkul QloApps Your Location Search stores cross site scripting
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1155?
CVE-2025-1155 is classified as problematic due to its cross site scripting capabilities.
How do I fix CVE-2025-1155?
To fix CVE-2025-1155, ensure to sanitize and validate user inputs in the Your Location Search component.
What impact does CVE-2025-1155 have on Webkul QloApps?
CVE-2025-1155 allows attackers to potentially execute arbitrary scripts in the context of a user's session.
Is remote exploitation possible with CVE-2025-1155?
Yes, CVE-2025-1155 can be exploited remotely, enabling threats from untrusted sources.
Which version of Webkul QloApps is affected by CVE-2025-1155?
CVE-2025-1155 affects Webkul QloApps version 1.6.1.