PT-2026-103629 · Qloapps · Qloapps
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
QloApps versions prior to 1.7.0
Description
A reflected cross-site scripting issue exists in the back-office room type editor's length of stay fields. Authenticated administrators can be induced to submit crafted POST requests containing malicious payloads via the
restriction min los and restriction max los parameters, allowing the execution of arbitrary JavaScript within the administrative session.Recommendations
Update to a version newer than 1.7.0.
Restrict access to the
restriction min los and restriction max los parameters in the room type editor to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qloapps