Security Advisory

CVE-2023-36288

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-23 00:00:00
Last updated 2024-11-29 19:30:45
Assigner mitre
State PUBLISHED

Description

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a users session cookie and then impersonate that user via GET configure parameter.