Impact
The vulnerability allows authenticated back‑office users to read arbitrary files via the getEmailHTML action of admin/ajax.php. By supplying relative path sequences in the email parameter, an attacker can bypass the directory restrictions and retrieve sensitive files such as database credentials and configuration information.
Affected Systems
QloApps by Webkul, versions up through 1.7.0 are affected. No specific minor release details are listed beyond the 1.7.0 cutoff.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation. The vulnerability is exploitable only by users who are authenticated to the back‑office; thus an attacker must compromise or trick a legitimate administrator to supply the crafted email parameter. Once authenticated, the attacker can read arbitrary files, leading to potential disclosure of confidential data and compromise of system integrity.
OpenCVE Enrichment