CVE-2021-41074

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
References
Link Resource
https://github.com/dillonkirsch/CVE-2021-41074 Third Party Advisory
https://qloapps.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:qloapps:1.5.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-12 21:15

Updated : 2026-01-22 18:45


NVD link : CVE-2021-41074

Mitre link : CVE-2021-41074

CVE.ORG link : CVE-2021-41074


JSON object : View

Products Affected

webkul

  • qloapps
CWE
CWE-352

Cross-Site Request Forgery (CSRF)