← Back to overview

CVE-2026-75496 affects Webkul QloApps, a hotel booking and management platform. The vulnerability stems from improper validation of uploaded file extensions and MIME types before files are moved to a publicly accessible directory. A remote, authenticated attacker with administrative privileges can exploit this flaw to upload executable files and achieve remote code execution on the server. The issue has been patched in commit 153ec1c. The vulnerability is classified as high severity due to its potential for full server compromise, though exploitation requires authenticated administrative access.

Affected products

  • Webkul QloApps

Related CVE's

  • CVE-2026-75496

Categories

  • Enterprise Applications
  • Web Technologies