QloApps 1.7.0 及更早版本存在一个反射型跨站脚本(XSS)漏洞,位于后台“移植模块”表单的 字段中。攻击者可以构造一个包含 JavaScript 载荷的恶意链接,该载荷嵌入在 参数中。当已认证的管理员点击并访问该链接时,恶意脚本将在其会话中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103587 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters |
| CVE-2026-103589 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via Room Type Editor |
| CVE-2026-103590 | 5.4 MEDIUM | QloApps through 1.7.0 Reflected XSS via Length of Stay Fields |
No comments yet