PT-2026-2299 · Unknown · Qloapps Hotel Ecommerce

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2021-41074

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QloApps hotel eCommerce version 1.5.1
Description A Cross-Site Request Forgery (CSRF) issue exists in the index.php file. This allows an attacker to modify the administrator's email address by leveraging a malicious HTML document.
Recommendations Update QloApps hotel eCommerce to a newer version that addresses this issue. As a temporary workaround, consider implementing CSRF protection mechanisms within the index.php file.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-41074

Affected Products

Qloapps Hotel Ecommerce