CVE-2026-92234
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
वीकनेस
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
संदर्भ
- https://github.com/Qloapps/QloApps
- https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php
- https://github.com/Qloapps/QloApps/commit/54a3b30e4e5c2d6b224dc8fe55e75db173064b91
- https://github.com/Qloapps/QloApps/pull/1796
- https://hackmd.io/@leediay/r1aoFrMFGl
- https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-hotel-feature-validation-errors
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।