← Vulnerability feed

Vulnerability record · CVE-2021-41074 · published 12 January 2026

CVE-2021-41074: Webkul qloapps cross-site request forgery vulnerability

Webkul · Qloapps

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

5.4 CVSS 3.1 Medium EPSS 0.14% · top 97.0% CWE-352 · Cross-site request forgery
5.4CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41074 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67325Webkul qloapps unrestricted file upload vulnerabilityUnrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …EPSS 0.92%7.5CVE-2023-36284Webkul qloapps sql injection vulnerabilityAn unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attack…EPSS 3.2%7.2CVE-2024-40318Webkul qloapps unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 1.2%6.5CVE-2023-36235Webkul qloapps insecure direct object reference vulnerabilityAn issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.EPSS 0.66%6.1CVE-2023-36287Webkul qloapps cross-site scripting vulnerabilityAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and th…EPSS 1.2%6.1CVE-2023-36289Webkul qloapps cross-site scripting vulnerabilityAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and th…EPSS 1.2%6.1CVE-2023-30256Webkul qloapps cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_cr…EPSS 9.1%5.5CVE-2025-10759Webkul qloapps improper authorization vulnerabilityA vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2021-41074), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.