CVE-2025-26058 - CERT CVE
ID CVE-2025-26058
Sažetak Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
Reference
CVSS
Base: 4.2
Impact: 3.4
Exploitability:0.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 19-02-2025 - 21:15
Objavljeno 18-02-2025 - 18:15