Beveiligingsadvies

CVE-2026-75496

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 16:36:42
Laatst bijgewerkt 2026-08-25 18:05:38
Toegewezen door cisa-cg
CVSS-score 8.6
Status PUBLISHED

Beschrijving

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.