CVE-2026-103588
Deferred Deferred - Pending Action

Reflected XSS in QloApps Back-Office Module Transplant Form

Vulnerability report for CVE-2026-103588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qloapps qloapps to 1.7.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in QloApps version 1.7.0 or earlier. It exists in the back-office Transplant a module form where the exceptions field does not properly sanitize user input. Attackers can inject malicious JavaScript code via the exceptions parameter in a crafted URL. When an authenticated administrator follows this link, the script executes within their session, potentially allowing unauthorized actions or data theft.

Detection Guidance

To detect this vulnerability, inspect HTTP requests to the QloApps back-office for the 'exceptions' parameter containing JavaScript payloads. Check logs for reflected XSS attempts in the Transplant a module form. Manually review the parameter in requests to /admin-dev/index.php?controller=AdminModules&action=transplant-module.

Impact Analysis

If you are an administrator of a vulnerable QloApps instance, an attacker could trick you into clicking a malicious link. This could lead to session hijacking, theft of sensitive data, or unauthorized administrative actions. For regular users, the impact is indirect unless the administrator's session is compromised, which could affect the entire application.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. If exploited, it may result in data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Update QloApps to the latest version beyond 1.7.0. Apply input validation to sanitize the 'exceptions' parameter in the Transplant a module form. Implement Content Security Policy (CSP) headers to mitigate XSS impact. Restrict access to the back-office to trusted administrators only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart