Path Traversal Vulnerability in QloApps by QloApps
CVE-2026-93988
Key Information:
Badges
What is CVE-2026-93988?
QloApps version 1.7.0 contains a path traversal vulnerability in the 'getEmailHTML' function of admin/ajax.php. This issue allows authenticated back-office users to perform unauthorized operations by supplying relative path sequences through the email parameter. As a result, attackers can bypass directory restrictions to access sensitive files, potentially exposing critical information such as database credentials and configuration data. This vulnerability poses a significant risk to the security and integrity of the affected systems.
Affected Version(s)
qloapps 0 <= 1.7.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
