A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul qloapps |
|
| CPEs | cpe:2.3:a:webkul:qloapps:1.5.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
Mon, 12 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Mon, 12 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-12T00:00:00.000Z
Updated: 2026-01-12T20:24:00.855Z
Reserved: 2021-09-14T00:00:00.000Z
Link: CVE-2021-41074
Updated: 2026-01-12T20:23:23.069Z
Status : Analyzed
Published: 2026-01-12T21:15:57.340
Modified: 2026-01-22T18:45:07.997
Link: CVE-2021-41074
No data.