CVE-2026-103589

Published: Ott 01, 2026 Last Modified: Ott 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,4
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none

Description

AI Translation Available

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.

79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stable
Common Consequences
Security Scopes Affected:
Access Control Confidentiality Integrity Availability
Potential Impacts:
Bypass Protection Mechanism Read Application Data Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: AI/ML, Web Based, Web Server
View CWE Details
https://github.com/Qloapps/QloApps
https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/co…
https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e8…
https://github.com/Qloapps/QloApps/pull/1899
https://hackmd.io/@leediay/four-reflected-xss-qloapps
https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-ro…