A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
References
| Link | Resource |
|---|---|
| https://github.com/dillonkirsch/CVE-2021-41074 | Third Party Advisory |
| https://qloapps.com/ | Product |
Configurations
History
No history.
Information
Published : 2026-01-12 21:15
Updated : 2026-01-22 18:45
NVD link : CVE-2021-41074
Mitre link : CVE-2021-41074
CVE.ORG link : CVE-2021-41074
JSON object : View
Products Affected
webkul
- qloapps
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
