PT-2026-108128 · Webkul · Qloapps

·

CVE-2026-107702

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id hotel parameter. Attackers can modify the id hotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107702

Affected Products

Qloapps