Impact
QloApps up to version 1.7.0 contains a reflected cross‑site scripting flaw because back‑office list filter POST parameters are rendered without escaping into HTML input value attributes. An attacker who can convince an authenticated administrator to submit a crafted POST request to a list controller can inject arbitrary JavaScript that executes within the victim’s session. This allows reading sensitive administrative information, manipulating tasks or hijacking the session. The weakness aligns with CWE‑79.
Affected Systems
The affected software is the QloApps e‑commerce platform developed by Webkul; every release up to and including version 1.7.0 is vulnerable. No further sub‑version at or before 1.7.0 are considered at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the exploit requires a legitimate administrator to be authenticated and to submit a malicious POST request. The EPSS score of less than 1 % points to a low probability of exploitation at the current time. The flaw is not listed in CISA’s KEV catalog, suggesting that widespread attacks have not yet been detected. However, because the vulnerability’s exploited code runs with administrative privileges, it presents a notable risk to the confidentiality, integrity, and availability of back‑office data and functions.
OpenCVE Enrichment