Impact
The vulnerability is a reflected cross‑site scripting flaw in QloApps version 1.7.0 and earlier, where the back‑office Hotel Reservation System Book Now search copies the date_to and id_room_type parameters directly into template variables without validation. The flaw falls under CWE‑79. An attacker can embed a JavaScript payload in the parameters and have it execute in the context of an authenticated administrator’s session when the victim opens the crafted link. The impact is the theft or tampering of administrative capabilities, but the scope is limited to users who can log into the back office.
Affected Systems
Affected vendor is Webkul: QloApps. The flaw exists in all releases up through 1.7.0. No version details are listed beyond the 1.7.0 cutoff; later releases may have fixed the issue.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk. The EPSS score is missing, and the vulnerability is not listed in CISA KEV, suggesting a low to moderate probability of exploitation. However, an attacker who can target a logged‑in administrator via a phishing email or an embedded link can achieve script execution, so the overall risk to an organization with an active back‑office login is increased. The attack vector is likely a crafted link that an administrator clicks, so internal or external users with access to the back office may be exposed.
OpenCVE Enrichment