Impact
The vulnerability is a reflected cross‑site scripting flaw in the exceptions field of the back‑office Transplant a module form. When an authenticated administrator opens a crafted URL containing malicious JavaScript in the exceptions parameter, the script executes in the administrator’s browser session. This allows an attacker to run arbitrary code while the victim is logged in as a privileged user, potentially leading to session hijacking, credential theft, or defacement of the administration interface.
Affected Systems
The weakness affects installations of Webkul QloApps version 1.7.0 or earlier. The affected code resides in the AdminModulesPositions controller of the back‑office, so any deployment that has not yet upgraded beyond 1.7.0 is vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. Since no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, no public exploitation is documented, but the attack can be performed remotely by delivering a malicious link to an authenticated administrator. The required precondition is a logged‑in privileged user who clicks the link, making the risk contingent on the security practices surrounding privileged account access.
OpenCVE Enrichment