SQL Injection Vulnerability in Webkul QloApps Affects Database Security
CVE-2026-75498
8.6HIGH
What is CVE-2026-75498?
A vulnerability in Webkul QloApps allows remote, authenticated attackers with administrative privileges to manipulate database queries through the 'bo_query' parameter in the 'Address.php' file. This weakness arises due to the application's failure to validate request parameters properly, enabling the execution of arbitrary SQL commands. A patch has been released to address this issue, ensuring better input validation to protect against such attacks.
Affected Version(s)
QloApps 0 < 123c97c
QloApps 123c97c
