Reflected Cross-Site Scripting in QloApps Admin Module by QloApps
CVE-2026-103588
5.1MEDIUM
What is CVE-2026-103588?
QloApps version 1.7.0 has a reflected cross-site scripting vulnerability that affects the exceptions field within the back-office 'Transplant a module' form. An attacker can exploit this vulnerability by crafting a specially crafted URL with a malicious JavaScript payload in the exceptions parameter. When an authenticated administrator clicks on the link, the malicious script executes within their session, potentially allowing the attacker to perform unauthorized actions.
Affected Version(s)
QloApps 0 <= 1.7.0
