PT-2026-103626 · Qloapps · Qloapps

·

CVE-2026-103587

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QloApps versions prior to 1.7.1
Description A reflected cross-site scripting issue exists in the back-office Hotel Reservation System Book Now search. The application fails to validate the date to and id room type parameters before copying them into template variables. This allows an attacker to execute a JavaScript payload within the session of an authenticated administrator by tricking them into following a specially crafted link.
Recommendations Update QloApps to version 1.7.1 or later. As a temporary mitigation, restrict access to the back-office Hotel Reservation System Book Now search or avoid using the date to and id room type parameters until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103587

Affected Products

Qloapps