Impact
QloApps through version 1.7.0 contains an authorization bypass in AdminHotelRoomsBookingController::postProcess(). By supplying an arbitrary id_hotel value in the Book Now page URL, users with back‑office employee accounts can query room availability and booking status for hotels outside their assigned profile. The flaw is driven by improper access validation (CWE-639), allowing restricted personnel to view confidential data belonging to other hotel accounts.
Affected Systems
The vulnerability affects the Webkul QloApps e‑commerce platform, specifically versions up to and including 1.7.0. All installations running this version of the hotel reservations module (hotelreservationsystem) are impacted because the AdminHotelRoomsBookingController is exposed to privileged users who can alter the id_hotel parameter.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is manipulating the id_hotel query string on the Book Now page, which is typically accessible to back‑office employees through the admin interface. If exploited, the attacker could obtain non‑authorized access to booking data of other hotels, potentially compromising confidentiality and integrity of the affected accounts for the compromised tenants.
OpenCVE Enrichment