Impact
QloApps versions up to 1.7.0 reflect unescaped child feature names in back‑office validation error messages. An authenticated back‑office user who follows a crafted link containing malicious child_features input can execute arbitrary JavaScript within the administrative session. This client‑side code execution can lead to session hijacking, credential theft, or the execution user is logged in.
Affected Systems
The vulnerability affects the QloApps application provided by Webkul, specifically all releases up to and including version 1.7.0. All users with access to the back‑office Hotel Reservation System administration interface are potentially impacted.
Risk and Exploitability
The flaw carries a CVSS score of 5.1, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalogue. Attacks require the attacker to already have authenticated back‑office access or to trick a legitimate user into clicking the crafted link. Exploitation is straightforward as it relies on reflected XSS via a predictable parameter, so any user with voting privileges could potentially trigger it.
OpenCVE Enrichment