CVE-2026-75496 UNKNOWN

CVE-2026-75496

Published: 2026-08-25

Description

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…