CVE-2025-6173: Webkul QloApps ajax_products_list.php sql injection
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajaxproductslist.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6173?
CVE-2025-6173 is classified as a critical vulnerability due to its potential for remote SQL injection.
How does CVE-2025-6173 occur?
CVE-2025-6173 occurs through manipulation of the 'packItself' argument in the /admin/ajax_products_list.php file.
What software is affected by CVE-2025-6173?
CVE-2025-6173 affects Webkul QloApps version 1.6.1.
How can I fix CVE-2025-6173?
To fix CVE-2025-6173, update Webkul QloApps to the latest version that addresses this SQL injection vulnerability.
Can CVE-2025-6173 be exploited remotely?
Yes, CVE-2025-6173 can be exploited remotely, allowing attackers to execute unauthorized SQL commands.