CVE-2026-103589
Deferred Deferred - Pending Action

Reflected XSS in QloApps Back-Office Room Type Editor

Vulnerability report for CVE-2026-103589, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qloapps qloapps 1.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a reflected cross-site scripting (XSS) flaw in QloApps version 1.7.0 or earlier. It occurs in the back-office room type editor where user input for room_num, floor, and comment fields is not properly escaped when rendered in HTML attributes. Attackers can trick authenticated back-office users into submitting malicious POST requests, leading to arbitrary JavaScript execution within the victim's administrative session.

Detection Guidance

To detect this reflected XSS vulnerability in QloApps, monitor POST requests to the back-office room type editor for unescaped input in room_num, floor, or comment fields. Check for JavaScript payloads in these parameters during user interactions. Use browser developer tools to inspect network requests for suspicious payloads.

Impact Analysis

If exploited, this vulnerability allows attackers to execute malicious JavaScript in the context of an authenticated back-office user. This could lead to session hijacking, unauthorized actions on behalf of the user, or theft of sensitive data such as credentials or customer information stored in the system.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using affected QloApps versions may face compliance violations, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Upgrade QloApps to the latest version beyond 1.7.0. Apply input validation and output encoding to escape room_num, floor, and comment fields in the back-office room type editor. Implement Content Security Policy (CSP) headers to mitigate XSS impact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103589. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart