CVE-2026-75496: Webkul QloApps improper file upload validation
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 153ec1c
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires remote access and authenticated administrative privileges. An attacker without an administrator account is not described as able to exploit the vulnerability.
What is the potential impact of successful exploitation?
An administrator-level attacker could upload an executable file to a publicly accessible directory and achieve remote code execution. The stated impact includes high confidentiality, integrity, and availability impact.
What should be done to remediate the issue?
Update to a QloApps version that includes commit 153ec1c, which is identified as the fix. The provided data does not specify a release version containing that commit.