VA-26-237-01

Vulnerability from csaf_cisa - Published: 2026-08-25 16:12 - Updated: 2026-08-25 16:12
Summary
Webkul QloApps multiple vulnerabilities
Notes
Legal Notice: All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).
Countries and Areas Deployed: Worldwide
Critical Infrastructure Sectors: Information Technology
Risk Evaluation: Webkul QloApps contains a remote code execution and SQL injection vulnerabilities. A remote attacker with administrative privileges could upload executable files and achieve remote code execution or send a crafted SQL query that bypasses validation.
Recommended Practices: Fixed in 153ec1c and 123c97c.
Company Headquarters Location: India
CWE-434 - Unrestricted Upload of File with Dangerous Type
Affected products
Product Identifier Version Remediation
Webkul QloApps <153ec1c
Webkul / QloApps
<153ec1c
Vendor Fix fix
Product Identifier Version Remediation
Webkul QloApps 153ec1c
Webkul / QloApps
153ec1c
Vendor Fix fix
CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected products
Product Identifier Version Remediation
Webkul QloApps <123c97c
Webkul / QloApps
<123c97c
Vendor Fix fix
Product Identifier Version Remediation
Webkul QloApps 123c97c
Webkul / QloApps
123c97c
Vendor Fix fix
CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected products
Known affected 1 product, the same list as for CVE-2026-75497
Fixed 1 product, the same list as for CVE-2026-75497
Acknowledgments

{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).",
        "title": "Legal Notice"
      },
      {
        "category": "other",
        "text": "Worldwide",
        "title": "Countries and Areas Deployed"
      },
      {
        "category": "other",
        "text": "Information Technology",
        "title": "Critical Infrastructure Sectors"
      },
      {
        "category": "summary",
        "text": "Webkul QloApps contains a remote code execution and SQL injection vulnerabilities. A remote attacker with administrative privileges could upload executable files and achieve remote code execution or send a crafted SQL query that bypasses validation.",
        "title": "Risk Evaluation"
      },
      {
        "category": "general",
        "text": "Fixed in 153ec1c and 123c97c.",
        "title": "Recommended Practices"
      },
      {
        "category": "other",
        "text": "India",
        "title": "Company Headquarters Location"
      }
    ],
    "publisher": {
      "category": "coordinator",
      "contact_details": "https://www.cisa.gov/report",
      "issuing_authority": "CISA",
      "name": "CISA",
      "namespace": "https://www.cisa.gov/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Vulnerability Advisory VA-26-237-01 CSAF",
        "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
      }
    ],
    "title": "Webkul QloApps multiple vulnerabilities",
    "tracking": {
      "current_release_date": "2026-08-25T16:12:44Z",
      "generator": {
        "engine": {
          "name": "VINCE-NT",
          "version": "1.15.0+build.101"
        }
      },
      "id": "VA-26-237-01",
      "initial_release_date": "2026-08-25T16:12:44Z",
      "revision_history": [
        {
          "date": "2026-08-25T16:12:44Z",
          "number": "1.0.0",
          "summary": "Initial publication"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c153ec1c",
                "product": {
                  "name": "Webkul QloApps \u003c153ec1c",
                  "product_id": "CSAFPID-0001"
                }
              },
              {
                "category": "product_version",
                "name": "153ec1c",
                "product": {
                  "name": "Webkul QloApps 153ec1c",
                  "product_id": "CSAFPID-0002"
                }
              },
              {
                "category": "product_version_range",
                "name": "\u003c123c97c",
                "product": {
                  "name": "Webkul QloApps \u003c123c97c",
                  "product_id": "CSAFPID-0003"
                }
              },
              {
                "category": "product_version",
                "name": "123c97c",
                "product": {
                  "name": "Webkul QloApps 123c97c",
                  "product_id": "CSAFPID-0004"
                }
              }
            ],
            "category": "product_name",
            "name": "QloApps"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c153ec1c",
                "product": {
                  "name": "Webkul QloApps \u003c153ec1c",
                  "product_id": "CSAFPID-0005"
                }
              },
              {
                "category": "product_version",
                "name": "153ec1c",
                "product": {
                  "name": "Webkul QloApps 153ec1c",
                  "product_id": "CSAFPID-0006"
                }
              },
              {
                "category": "product_version_range",
                "name": "\u003c123c97c",
                "product": {
                  "name": "Webkul QloApps \u003c123c97c",
                  "product_id": "CSAFPID-0007"
                }
              },
              {
                "category": "product_version",
                "name": "123c97c",
                "product": {
                  "name": "Webkul QloApps 123c97c",
                  "product_id": "CSAFPID-0008"
                }
              }
            ],
            "category": "product_name",
            "name": "QloApps"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "\u003c153ec1c",
                "product": {
                  "name": "Webkul QloApps \u003c153ec1c",
                  "product_id": "CSAFPID-0009"
                }
              },
              {
                "category": "product_version",
                "name": "153ec1c",
                "product": {
                  "name": "Webkul QloApps 153ec1c",
                  "product_id": "CSAFPID-0010"
                }
              },
              {
                "category": "product_version_range",
                "name": "\u003c123c97c",
                "product": {
                  "name": "Webkul QloApps \u003c123c97c",
                  "product_id": "CSAFPID-0011"
                }
              },
              {
                "category": "product_version",
                "name": "123c97c",
                "product": {
                  "name": "Webkul QloApps 123c97c",
                  "product_id": "CSAFPID-0012"
                }
              }
            ],
            "category": "product_name",
            "name": "QloApps"
          }
        ],
        "category": "vendor",
        "name": "Webkul"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "leediay153"
          ]
        }
      ],
      "cve": "CVE-2026-75496",
      "cwe": {
        "id": "CWE-434",
        "name": "Unrestricted Upload of File with Dangerous Type"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:P/A:N/T:T/2026-08-17T20:27:36Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0002"
        ],
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "github.com",
          "url": "https://github.com/Qloapps/QloApps/pull/1801/commits/153ec1c8567798bd99155098ecc0a340e38f25bf"
        },
        {
          "category": "external",
          "summary": "VA-26-237-01 CSAF",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
        },
        {
          "category": "external",
          "summary": "CVE-2026-75496",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75496"
        }
      ],
      "release_date": "2026-07-20T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-20T00:00:00Z",
          "details": "Fixed in 153ec1c.",
          "product_ids": [
            "CSAFPID-0001"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1801/commits/153ec1c8567798bd99155098ecc0a340e38f25bf"
        },
        {
          "category": "vendor_fix",
          "date": "2026-07-20T00:00:00Z",
          "details": "Fixed in 153ec1c.",
          "product_ids": [
            "CSAFPID-0002"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1801/commits/153ec1c8567798bd99155098ecc0a340e38f25bf"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "Webkul QloApps improper file upload validation"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "leediay153"
          ]
        }
      ],
      "cve": "CVE-2026-75497",
      "cwe": {
        "id": "CWE-89",
        "name": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027CustomerMessage.php\u0027 file. Fixed in 123c97c.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:P/A:N/T:T/2026-08-18T14:32:30Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0004"
        ],
        "known_affected": [
          "CSAFPID-0003"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "github.com",
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        },
        {
          "category": "external",
          "summary": "VA-26-237-01 CSAF",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
        },
        {
          "category": "external",
          "summary": "CVE-2026-75497",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75497"
        }
      ],
      "release_date": "2026-08-13T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-13T00:00:00Z",
          "details": "Fixed in 123c97c.",
          "product_ids": [
            "CSAFPID-0003"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        },
        {
          "category": "vendor_fix",
          "date": "2026-08-13T00:00:00Z",
          "details": "Fixed in 123c97c.",
          "product_ids": [
            "CSAFPID-0004"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0003"
          ]
        }
      ],
      "title": "Webkul QloApps SQL injection"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "leediay153"
          ]
        }
      ],
      "cve": "CVE-2026-75498",
      "cwe": {
        "id": "CWE-89",
        "name": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027Address.php\u0027 file. Fixed in 123c97c.",
          "title": "Description"
        },
        {
          "category": "details",
          "text": "SSVCv2/E:P/A:N/T:T/2026-08-18T14:33:09Z/",
          "title": "SSVC"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0004"
        ],
        "known_affected": [
          "CSAFPID-0003"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "github.com",
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        },
        {
          "category": "external",
          "summary": "VA-26-237-01 CSAF",
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
        },
        {
          "category": "external",
          "summary": "CVE-2026-75498",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75498"
        }
      ],
      "release_date": "2026-08-13T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-13T00:00:00Z",
          "details": "Fixed in 123c97c.",
          "product_ids": [
            "CSAFPID-0003"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        },
        {
          "category": "vendor_fix",
          "date": "2026-08-13T00:00:00Z",
          "details": "Fixed in 123c97c.",
          "product_ids": [
            "CSAFPID-0004"
          ],
          "url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0003"
          ]
        }
      ],
      "title": "Webkul QloApps SQL injection"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…