Webkul QloApps Insecure Token Exposure Vulnerability

Vulnerability

A vulnerability in Webkul QloApps version 1.6.1 allows authentication tokens to be exposed in URLs during redirection. This occurs when users access the admin panel or other protected areas, with the application appending sensitive tokens directly to the URL. This exposure poses significant security risks, including unauthorized access, session hijacking, and privilege escalation.

Impact

Exploitation of this vulnerability could lead to unauthorized access to administrative functions, session hijacking, and account takeovers.

Reproduction

To reproduce this vulnerability, access the admin panel URL. The application will redirect to a URL that includes a sensitive authentication token. This token can be seen in the URL, intercepted, logged, or manipulated.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
5.0
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.