PT-2026-103626 · Qloapps · Qloapps
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
QloApps versions prior to 1.7.1
Description
A reflected cross-site scripting issue exists in the back-office Hotel Reservation System Book Now search. The application fails to validate the
date to and id room type parameters before copying them into template variables. This allows an attacker to execute a JavaScript payload within the session of an authenticated administrator by tricking them into following a specially crafted link.Recommendations
Update QloApps to version 1.7.1 or later.
As a temporary mitigation, restrict access to the back-office Hotel Reservation System Book Now search or avoid using the
date to and id room type parameters until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qloapps