Authorization Bypass in QloApps Affects Data Privacy for Hotels
CVE-2026-107702
5.3MEDIUM
What is CVE-2026-107702?
QloApps version 1.7.0 features an authorization bypass vulnerability in the AdminHotelRoomsBookingController, specifically in the postProcess() function. This flaw allows unauthorized back-office employees to access sensitive information regarding other hotels by manipulating the 'id_hotel' URL parameter. An attacker could exploit this vulnerability to gain visibility into room availability and booking statuses of hotels that are outside their authorized access, compromising the integrity and confidentiality of hotel data.
Affected Version(s)
QloApps 0 <= 1.7.0
