CVE-2026-103588: QloApps through 1.7.0 Reflected XSS via exceptions field
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Authenticated QloApps administrators are the intended victims. An attacker must induce an administrator to follow a crafted link while the administrator has an active session.
What access does an attacker need to exploit it?
The attack can be delivered remotely through a malicious link and does not require the attacker to authenticate. Successful exploitation requires user interaction because an authenticated administrator must follow the link.
Which functionality is affected?
The affected input is the exceptions field in the back-office Transplant a module form. JavaScript supplied through the exceptions parameter can execute in the administrator's browser session.
What can the attacker do if exploitation succeeds?
The provided impact data indicates low confidentiality and integrity impact, with no availability impact. Because the script runs in an authenticated administrator session, it may act within the browser context available to that administrator.