← back
CVE-2025-26058

CVE-2025-26058

CVSS 4.2 MEDIUMEPSS 0.2%CWE-598
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.2EPSS 0.2%KEV nãoPoC Patch
Lifecycle
18 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →