Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul qloapps |
|
| Vendors & Products |
Webkul
Webkul qloapps |
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c. | |
| Title | Webkul QloApps SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-08-25T18:05:58.384Z
Reserved: 2026-08-17T20:16:01.457Z
Link: CVE-2026-75497
Updated: 2026-08-25T18:05:54.578Z
Status : Received
Published: 2026-08-25T17:18:16.187
Modified: 2026-08-25T18:18:03.100
Link: CVE-2026-75497
No data.
OpenCVE Enrichment
Updated: 2026-08-25T21:00:04Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')