CVE-2025-10759 is an authorization bypass vulnerability in Webkul QloApps up to version 1.7.0, specifically within its CSRF Token Handler. An attacker can remotely manipulate the 'token' argument to bypass authorization, potentially leading to unauthorized actions. Rated as Medium severity (CVSS 5.3), this vulnerability has a low attack complexity and could result in limited integrity impact. While the exploit is publicly available, there is no evidence of active exploitation, and it currently lacks significant community discussion or media coverage. The vendor is aware and plans to address it in a future major release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.