Executive brief
Webkul QloApps is an open-source e-commerce and customer relationship management platform. The application fails to properly validate uploaded file types and MIME types before storing files in web-accessible directories. An authenticated administrator can exploit this to upload and execute malicious code on the server, gaining complete control over the application and underlying system.
Technical details
This is an arbitrary file upload vulnerability with insufficient input validation on file extensions and MIME types. The vulnerable component accepts file uploads in administrative flows without properly validating that the uploaded file matches expected safe types (e.g., images, documents), allowing an attacker to bypass restrictions and upload executable files such as PHP scripts. The root cause is missing or inadequate server-side validation of uploaded file content and extension. An authenticated attacker with administrative privileges can upload executable files to publicly accessible directories and achieve remote code execution. The vulnerability has been patched in commit 153ec1c through improved input and file-upload validation across admin flows.
Affected products
- Webkul QloApps prior to commit 153ec1c
Timeline
- 2026-08-25: disclosed
- 2026-07-20: patched: Fix commit 153ec1c merged on 2026-08-24