Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107702— QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking

Quick assessment

Affected
Webkul QloApps
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 QloApps 1.7.0 及之前版本中,AdminHotelRoomsBookingController::postProcess() 方法存在一个授权绕过漏洞。攻击者可以通过提供 参数,使受限制的后台员工能够访问其他酒店的数据。具体来说,攻击者可以在“立即预订”(Book Now)页面修改 URL 参数中的 ,从而查看超出其权限范围的其他酒店的房间可用性和预订状态。

CVSS 4.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Webkul QloApps ≤ 1.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107702

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking
Source: CVE Program / CVE List V5
Vulnerability Description
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by supplying an id_hotel parameter. Attackers can modify the id_hotel URL parameter on the Book Now page to view room availability and booking status of hotels outside their assigned profile access.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Webkul QloApps 0 ~ 1.7.0 -

II. Public POCs for CVE-2026-107702

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107702

请登录查看更多情报信息。

Other References for CVE-2026-107702 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107702

No comments yet


Leave a comment