QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "64e9722e7e6a8fda77dd53964d988fb6b5c3d174"
},
{
"last_affected": "64e9722e7e6a8fda77dd53964d988fb6b5c3d174"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-916"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25861.json",
"cna_assigner": "VulnCheck"
}