CSRF Token Bypass Vulnerability in Webkul QloApps by Webkul
CVE-2025-10759
Key Information:
Badges
What is CVE-2025-10759?
A vulnerability has been identified in Webkul QloApps versions up to 1.7.0, affecting the CSRF Token Handler component. This vulnerability allows for potential authorization bypass through manipulation of the token argument. The attack can be executed remotely, raising significant security concerns. The vendor has acknowledged this issue and is actively working on a resolution, with plans to implement fixes in an upcoming major release. As this exploit is now public, users are advised to take necessary precautions.
Affected Version(s)
QloApps 1.0
QloApps 1.1
QloApps 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved