Webkul QloApps
cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*
- 1.6.1
A vulnerability in Webkul QloApps version 1.6.1 allows authentication tokens to be exposed in URLs during redirection. This occurs when users access the admin panel or other protected areas, with the application appending sensitive tokens directly to the URL. This exposure poses significant security risks, including unauthorized access, session hijacking, and privilege escalation.
Exploitation of this vulnerability could lead to unauthorized access to administrative functions, session hijacking, and account takeovers.
To reproduce this vulnerability, access the admin panel URL. The application will redirect to a URL that includes a sensitive authentication token. This token can be seen in the URL, intercepted, logged, or manipulated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.