9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
AI Analysis
Unrestricted file upload vulnerability allowing remote code execution
Basic Information
ID
CVE-2025-67325
Source
mitre
Published
Jan 8, 2026 at 00:00
Modified
Jan 8, 2026 at 19:00
Affected Product
Vendor
Qloapps
Product
QloApps
Version
1.7.0 and earlier
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Qloapps
Product
QloApps
Version
1.7.0 and earlier