CVE-2025-67325

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
References
Link Resource
https://github.com/Qloapps/QloApps Product
https://github.com/mr7s3d0/CVE-2025-67325 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*

History

30 Jan 2026, 01:06

Type Values Removed Values Added
CPE cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*
References () https://github.com/Qloapps/QloApps - () https://github.com/Qloapps/QloApps - Product
References () https://github.com/mr7s3d0/CVE-2025-67325 - () https://github.com/mr7s3d0/CVE-2025-67325 - Exploit, Third Party Advisory
First Time Webkul qloapps
Webkul

08 Jan 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 19:15

Updated : 2026-01-30 01:06


NVD link : CVE-2025-67325

Mitre link : CVE-2025-67325

CVE.ORG link : CVE-2025-67325


JSON object : View

Products Affected

webkul

  • qloapps
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type