CVE-2025-1074
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 6, 2025
CWE ID 352
CWE ID 862
Summary
CVE-2025-1074 is a recently disclosed vulnerability affecting the logout function in the URL Handler component of Webkul QloApps 1.6.1. This issue, classified as problematic, enables an attacker to perform cross-site request forgery, allowing them to manipulate user sessions and potentially launch attacks remotely. The vulnerability has been made public, increasing the risk of exploitation, and the vendor, Webkul, has been made aware and is working on a resolution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Webkul