CSRF Vulnerability in QloApps Hotel eCommerce by QloApps
CVE-2021-41074
5.4MEDIUM
What is CVE-2021-41074?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the index.php file of QloApps hotel eCommerce version 1.5.1. This flaw permits an attacker to change the email address associated with an admin account by leveraging a specially crafted HTML document, potentially leading to further security breaches within the management system.
