← Vulnerability feed

Vulnerability record · CVE-2023-30256 · published 11 May 2023

CVE-2023-30256: Webkul qloapps cross-site scripting vulnerability

Webkul · Qloapps

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

6.1 CVSS 3.1 Medium EPSS 9.1% · top 4.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
9.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-30256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67325Webkul qloapps unrestricted file upload vulnerabilityUnrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …EPSS 0.92%7.5CVE-2023-36284Webkul qloapps sql injection vulnerabilityAn unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attack…EPSS 3.2%7.2CVE-2024-40318Webkul qloapps unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 1.2%6.5CVE-2023-36235Webkul qloapps insecure direct object reference vulnerabilityAn issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.EPSS 0.66%6.1CVE-2023-36287Webkul qloapps cross-site scripting vulnerabilityAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and th…EPSS 1.2%6.1CVE-2023-36289Webkul qloapps cross-site scripting vulnerabilityAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and th…EPSS 1.2%5.5CVE-2025-10759Webkul qloapps improper authorization vulnerabilityA vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…EPSS 0.35%5.4CVE-2021-41074Webkul qloapps cross-site request forgery vulnerabilityA CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.EPSS 0.14%

Source: NIST National Vulnerability Database (record CVE-2023-30256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.