← Vulnerability feed

Vulnerability record · CVE-2023-36289 · published 23 June 2023

CVE-2023-36289: Webkul qloapps cross-site scripting vulnerability

Webkul · Qloapps

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.

6.1 CVSS 3.1 Medium EPSS 1.2% · top 33.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36289 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67325Webkul qloapps unrestricted file upload vulnerabilityUnrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …EPSS 0.92%7.5CVE-2023-36284Webkul qloapps sql injection vulnerabilityAn unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attack…EPSS 3.2%7.2CVE-2024-40318Webkul qloapps unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 1.2%6.5CVE-2023-36235Webkul qloapps insecure direct object reference vulnerabilityAn issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.EPSS 0.66%6.1CVE-2023-36287Webkul qloapps cross-site scripting vulnerabilityAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and th…EPSS 1.2%6.1CVE-2023-30256Webkul qloapps cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_cr…EPSS 9.1%5.5CVE-2025-10759Webkul qloapps improper authorization vulnerabilityA vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…EPSS 0.35%5.4CVE-2021-41074Webkul qloapps cross-site request forgery vulnerabilityA CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.EPSS 0.14%

Source: NIST National Vulnerability Database (record CVE-2023-36289), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.