CVE-2026-103588: QloApps through 1.7.0 Reflected XSS via exceptions field

Published Sep 30, 2026
·
Updated

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.

Affected Software

1 affected component
QloApps QloApps<=1.7.0

Event History

Sep 30, 2026
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Aug 30, 58718
Event
via NVD·06:09 AM

Frequently Asked Questions

1

Who is exposed to this issue?

Authenticated QloApps administrators are the intended victims. An attacker must induce an administrator to follow a crafted link while the administrator has an active session.

2

What access does an attacker need to exploit it?

The attack can be delivered remotely through a malicious link and does not require the attacker to authenticate. Successful exploitation requires user interaction because an authenticated administrator must follow the link.

3

Which functionality is affected?

The affected input is the exceptions field in the back-office Transplant a module form. JavaScript supplied through the exceptions parameter can execute in the administrator's browser session.

4

What can the attacker do if exploitation succeeds?

The provided impact data indicates low confidentiality and integrity impact, with no availability impact. Because the script runs in an authenticated administrator session, it may act within the browser context available to that administrator.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203