QloApps 1.7.0 及更早版本的后端酒店预订系统“立即预订”搜索功能中存在反射型跨站脚本(XSS)漏洞。该漏洞源于 和 参数在被复制到模板变量时未进行任何验证。攻击者可构造包含 JavaScript 恶意代码的链接,当已认证的管理员点击该链接时,恶意脚本将在其会话中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103589 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via Room Type Editor |
| CVE-2026-103588 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via exceptions field |
| CVE-2026-103590 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via Length of Stay Fields |
No comments yet