Vulnerability Description
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webkul | Qloapps | 1.6.1 |
Related Weaknesses (CWE)
References
- https://github.com/mano257200/Qloapp-XSS-Vulnerability/tree/mainExploitThird Party Advisory
- https://vuldb.com/?ctiid.295059Permissions RequiredVDB Entry
- https://vuldb.com/?id.295059Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.492777Third Party AdvisoryVDB Entry
- https://github.com/mano257200/Qloapp-XSS-Vulnerability/tree/mainExploitThird Party Advisory
FAQ
What is CVE-2025-1155?
CVE-2025-1155 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads ...
How severe is CVE-2025-1155?
CVE-2025-1155 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1155?
Check the references section above for vendor advisories and patch information. Affected products include: Webkul Qloapps.