Impact
QloApps versions up to 1.7.0 contain a reflected cross‑site scripting flaw in the back‑office room type editor. By submitting a crafted POST request containing malicious payloads in the restriction_min_los and restriction_max_los parameters, an attacker can cause arbitrary JavaScript to be executed in the context of an authenticated administrator’s session, potentially allowing session hijacking or credential theft.
Affected Systems
The vulnerability affects Webkul’s QloApps product, specifically version 1.7.0. Only this version is cited as vulnerable.
Risk and Exploitability
The CVSS score is 5.1, indicating a medium severity. EPSS information is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires authenticated administrative access to the back‑office and the ability to send crafted POST requests; no publicly available exploit code is cited. The risk is moderate, but the impact on privileged users justifies timely remediation.
OpenCVE Enrichment