CVE-2026-103587
Deferred Deferred - Pending Action

Reflected XSS in QloApps Hotel Reservation System

Vulnerability report for CVE-2026-103587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qloapps qloapps to 1.7.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

QloApps through version 1.7.0 has a reflected cross-site scripting (XSS) vulnerability in the back-office Hotel Reservation System Book Now search feature. The date_to and id_room_type parameters are directly copied into template variables without proper validation or sanitization. This allows attackers to craft malicious links containing JavaScript code in these parameters. When an authenticated administrator follows such a link, the embedded script executes within their session, potentially leading to unauthorized actions or data theft.

Detection Guidance

To detect this reflected XSS vulnerability in QloApps, inspect HTTP requests to the back-office Hotel Reservation System Book Now search for the date_to and id_room_type parameters. Look for JavaScript payloads in these parameters, especially in responses from the server. Manually test by crafting URLs with payloads like <script>alert(1)</script> in these parameters and observe if they execute in an authenticated session.

No specific commands are provided in the context, but network monitoring tools like Wireshark or browser developer tools can help capture and analyze these requests.

Impact Analysis

If you are an administrator using QloApps 1.7.0 or earlier, clicking a malicious link could allow attackers to steal your session cookies, perform actions on your behalf, or access sensitive data. The impact depends on your privileges; as an admin, attackers might gain control over the system, modify settings, or exfiltrate user information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. If exploited, it may result in data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Immediately update QloApps to the latest version beyond 1.7.0 to patch the vulnerability. If an update is not available, apply input validation and output encoding to sanitize the date_to and id_room_type parameters in the back-office Hotel Reservation System Book Now search. Restrict access to the back-office to trusted administrators only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart