A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
References
| Link | Resource |
|---|---|
| https://github.com/dillonkirsch/CVE-2021-41074 | Third Party Advisory |
| https://qloapps.com/ | Product |
Configurations
History
22 Jan 2026, 18:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:webkul:qloapps:1.5.1:*:*:*:*:*:*:* | |
| References | () https://github.com/dillonkirsch/CVE-2021-41074 - Third Party Advisory | |
| References | () https://qloapps.com/ - Product | |
| First Time |
Webkul qloapps
Webkul |
12 Jan 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-12 21:15
Updated : 2026-01-22 18:45
NVD link : CVE-2021-41074
Mitre link : CVE-2021-41074
CVE.ORG link : CVE-2021-41074
JSON object : View
Products Affected
webkul
- qloapps
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
