Medium severity6.5NVD Advisory· Published Jan 17, 2024· Updated Jun 17, 2026
CVE-2023-36235
CVE-2023-36235
Description
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/webkul/hotelcommerce/pull/537nvdPatch
- github.com/Ek-Saini/security/blob/main/IDOR-QloappsnvdExploit
- qloapps.comnvdProduct
News mentions
0No linked articles in our index yet.