Impact
QloApps through version 1.7.0 contains a stored XSS flaw in the admin file manager that lets an authenticated administrator upload SVG files containing malicious JavaScript. By embedding event handlers such as onload, an attacker can cause arbitrary scripts to run in the browser of any user who later views the file, potentially leading to information disclosure, session hijacking or defacement. The flaw is a classic unsanitized input problem classified as CWE‑79.
Affected Systems
The vulnerable product is QloApps version 1.7.0 (and earlier), offered by the vendor QloApps. The flaw exists in the built‑in file manager that is accessible only to users with administrative privileges.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity; there is no EPSS data available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first gain administrative access to the site, after which the attacker can upload a crafted SVG file. Once uploaded, any user who opens the file will have the injected script executed in their browser. The risk is therefore limited to environments where administrators use the file manager and image files are displayed to end users, but the lack of a public exploit and moderate score suggest that the threat level is moderate.
OpenCVE Enrichment