Description
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side code execution via reflected XSS
Action: Patch promptly
AI Analysis

Impact

QloApps versions up to 1.7.0 reflect unescaped child feature names in back‑office validation error messages. An authenticated back‑office user who follows a crafted link containing malicious child_features input can execute arbitrary JavaScript within the administrative session. This client‑side code execution can lead to session hijacking, credential theft, or the execution user is logged in.

Affected Systems

The vulnerability affects the QloApps application provided by Webkul, specifically all releases up to and including version 1.7.0. All users with access to the back‑office Hotel Reservation System administration interface are potentially impacted.

Risk and Exploitability

The flaw carries a CVSS score of 5.1, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalogue. Attacks require the attacker to already have authenticated back‑office access or to trick a legitimate user into clicking the crafted link. Exploitation is straightforward as it relies on reflected XSS via a predictable parameter, so any user with voting privileges could potentially trigger it.

Generated by OpenCVE AI on September 18, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update QloApps to a version that includes the fix or apply the specific patch commit that sanitizes the child_features output.
  • Replace the AdminHotelfeaturesController.php file with the corrected version from the project repository or the official release version that eliminates the reflected XSS.
  • Ensure that all back‑office output, especially validation error messages, properly escape user‑supplied data to prevent XSS.

Generated by OpenCVE AI on September 18, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
Title QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors
First Time appeared Webkul
Webkul qloapps
Weaknesses CWE-79
CPEs cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul qloapps
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T18:02:11.766Z

Reserved: 2026-09-15T19:27:24.634Z

Link: CVE-2026-92234

cve-icon Vulnrichment

Updated: 2026-09-16T18:01:23.233Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:49.350

Modified: 2026-09-16T20:21:01.047

Link: CVE-2026-92234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')