{"id":"CVE-2026-93988","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-93988","summary":"QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers…","details":"QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.","published":"2026-09-19T23:17:09.890","modified":"2026-09-19T23:17:09.890","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715","label":"Qloapps/QloApps@8015495"},"references":[{"type":"WEB","url":"https://github.com/Qloapps/QloApps"},{"type":"WEB","url":"https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051"},{"type":"WEB","url":"https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715"},{"type":"WEB","url":"https://github.com/Qloapps/QloApps/pull/1719"},{"type":"WEB","url":"https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-19T23:17:09.890"}}