CVE-2023-30256: Webkul Qloapps

Medium severity, CVSS 6.1. EPSS: 9.1% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

Affected products

  • Webkul Qloapps: version 1.5.2 only

Published 2023-05-11. Last modified 2026-06-17.