PT-2026-2299 · Unknown · Qloapps Hotel Ecommerce

CVE-2021-41074

·

Publicado

2026-01-12

·

Atualizado

2026-01-12

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QloApps hotel eCommerce version 1.5.1
Description A Cross-Site Request Forgery (CSRF) issue exists in the index.php file. This allows an attacker to modify the administrator's email address by leveraging a malicious HTML document.
Recommendations Update QloApps hotel eCommerce to a newer version that addresses this issue. As a temporary workaround, consider implementing CSRF protection mechanisms within the index.php file.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-41074

Produtos afetados

Qloapps Hotel Ecommerce