CVE-2023-36287
- EPSS 20.46%
- Veröffentlicht 23.06.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:29
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
CVE-2023-36288
- EPSS 0.11%
- Veröffentlicht 23.06.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:09:29
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
CVE-2023-36289
- EPSS 23.72%
- Veröffentlicht 23.06.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:09:29
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
CVE-2023-30256
- EPSS 73.4%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:13
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.