Authorization Bypass in QloApps Affects Data Privacy for Hotels
CVE-2026-107702

5.3MEDIUM

Key Information:

Vendor

Webkul

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107702?

QloApps version 1.7.0 features an authorization bypass vulnerability in the AdminHotelRoomsBookingController, specifically in the postProcess() function. This flaw allows unauthorized back-office employees to access sensitive information regarding other hotels by manipulating the 'id_hotel' URL parameter. An attacker could exploit this vulnerability to gain visibility into room availability and booking statuses of hotels that are outside their authorized access, compromising the integrity and confidentiality of hotel data.

Affected Version(s)

QloApps 0 <= 1.7.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leediay153 from Viettel Post
.