PT-2026-103629 · Qloapps · Qloapps

·

CVE-2026-103590

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QloApps versions prior to 1.7.0
Description A reflected cross-site scripting issue exists in the back-office room type editor's length of stay fields. Authenticated administrators can be induced to submit crafted POST requests containing malicious payloads via the restriction min los and restriction max los parameters, allowing the execution of arbitrary JavaScript within the administrative session.
Recommendations Update to a version newer than 1.7.0. Restrict access to the restriction min los and restriction max los parameters in the room type editor to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103590

Affected Products

Qloapps