CVE-2026-93988
QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
| CWE | CWE-22 |
| Vendor | webkul |
| Product | qloapps |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for webkul qloapps
Be the first to know when new medium vulnerabilities affecting webkul qloapps are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
webkul / qloapps
0 โค 1.7.0
References
github.com: https://github.com/Qloapps/QloApps/pull/1719 github.com: https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715 github.com: https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051 hackmd.io: https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal github.com: https://github.com/Qloapps/QloApps vulncheck.com: https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml
Credits
๐ leediay153