Reflected XSS in QloApps Hotel Reservation System
CVE-2026-92234
5.1MEDIUM
What is CVE-2026-92234?
A reflected Cross-Site Scripting (XSS) vulnerability exists in QloApps versions up to 1.7.0, allowing authenticated back-office users to exploit unescaped child feature names displayed in validation error messages. By crafting a specific link, attackers can inject JavaScript code into the administrative session, which could lead to unauthorized actions and data exposure. Users of QloApps should update to the patched version to mitigate this risk.
Affected Version(s)
QloApps 0 <= 1.7.0
