CVE-2026-103590: QloApps through 1.7.0 Reflected XSS via Length of Stay Fields
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restrictionminlos and restrictionmaxlos parameters, executing arbitrary JavaScript in the victim's administrative session.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Back-office administrators who edit room types are exposed if they can be induced to submit a crafted POST request. The malicious script executes in the affected administrator's authenticated administrative session.
What does an attacker need to exploit it?
An attacker needs to cause an authenticated administrator to submit a crafted POST request containing malicious payloads in the restriction_min_los or restriction_max_los parameters. User interaction is required.
Which versions are affected?
QloApps through version 1.7.0 is affected.