PT-2026-47296 · Qloapps · Qloapps
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
QloApps versions prior to 1.7.1
Description
A stored cross-site scripting issue exists in the admin file manager. Authenticated administrators can inject malicious JavaScript by uploading specially crafted SVG files. By embedding JavaScript event handlers, such as
onload, within these files, arbitrary scripts can be executed in the browser of any user who views the uploaded file.Recommendations
Update to a version later than 1.7.0.
As a temporary mitigation, restrict the ability to upload SVG files through the admin file manager.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qloapps