Impact
A reflected cross‑site scripting flaw exists in the admin interface of QloApps up to version 1.7.0. The editor does not properly escape the values supplied for room_num, floor, and comment when they are included in HTML attribute contexts. An attacker can exploit this by crafting malicious POST data that, when rendered by a logged‑in administrator, executes arbitrary JavaScript inside the administrative session.
Affected Systems
Webkul QloApps versions 1.7.0 and earlier are affected. No narrower version identifiers are provided; all releases up to 1.7.0 contain the vulnerability.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog. Successful exploitation requires an authenticated back‑office user to submit a crafted POST request via the room type editor. Attackers can then run arbitrary JavaScript while the admin’s session is active, potentially compromising session data, credentials, or performing actions on behalf of the user.
OpenCVE Enrichment