Description
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 12 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions. | |
| Title | QloApps through 1.7.0 Reflected XSS via List Filter Parameters | |
| First Time appeared |
Webkul
Webkul qloapps |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T01:50:33.852Z
Reserved: 2026-09-11T10:52:56.669Z
Link: CVE-2026-89268
No data.
Status : Received
Published: 2026-09-12T02:16:24.623
Modified: 2026-09-12T02:16:24.623
Link: CVE-2026-89268
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')