Description
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting in admin UI
Action: Apply patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in QloApps version 1.7.0 and earlier, where the back‑office Hotel Reservation System Book Now search copies the date_to and id_room_type parameters directly into template variables without validation. The flaw falls under CWE‑79. An attacker can embed a JavaScript payload in the parameters and have it execute in the context of an authenticated administrator’s session when the victim opens the crafted link. The impact is the theft or tampering of administrative capabilities, but the scope is limited to users who can log into the back office.

Affected Systems

Affected vendor is Webkul: QloApps. The flaw exists in all releases up through 1.7.0. No version details are listed beyond the 1.7.0 cutoff; later releases may have fixed the issue.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate risk. The EPSS score is missing, and the vulnerability is not listed in CISA KEV, suggesting a low to moderate probability of exploitation. However, an attacker who can target a logged‑in administrator via a phishing email or an embedded link can achieve script execution, so the overall risk to an organization with an active back‑office login is increased. The attack vector is likely a crafted link that an administrator clicks, so internal or external users with access to the back office may be exposed.

Generated by OpenCVE AI on October 1, 2026 at 00:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade QloApps to the latest version that includes the fix for the reflected XSS in the Book Now search feature.
  • Sanitize all input parameters in the back‑office module, ensuring date_to and id_room_type are validated or encoded before rendering.
  • Deploy a content‑security‑policy that restricts inline scripts in the back‑office context, and if possible, disable the direct rendering of user‑supplied data.

Generated by OpenCVE AI on October 1, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
Title QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters
First Time appeared Webkul
Webkul qloapps
Weaknesses CWE-79
CPEs cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul qloapps
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T23:02:32.852Z

Reserved: 2026-09-30T22:31:58.851Z

Link: CVE-2026-103587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T23:16:58.027

Modified: 2026-09-30T23:16:58.170

Link: CVE-2026-103587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T00:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')