Executive brief
QloApps, an open-source hotel booking and reservation system, uses an outdated and weak method for securing user passwords. This flaw allows attackers who obtain the database to easily crack user passwords through automated guessing, potentially leading to unauthorized access to customer accounts and sensitive personal information. The risk is particularly high for accounts converted from guest status, which are assigned short, predictable passwords.
Technical details
QloApps through version 1.7.0 utilizes the MD5 hashing algorithm within the Tools::encrypt() function in classes/Tools.php to secure user passwords. The implementation concatenates a static cookie key with the password before hashing, which does not provide sufficient protection against modern offline brute-force attacks. Furthermore, the classes/Customer.php component auto-generates weak 8-character passwords during guest-to-customer account conversions, significantly reducing the entropy required for successful credential recovery. An attacker with access to the hashed credentials can trivially recover plaintext passwords. The issue was addressed in commit 64e9722 by migrating the hashing mechanism to bcrypt.
Affected products
- QloApps QloApps through 1.7.0
Timeline
- 2026-03-13: other: Pull request initiated
- 2026-05-19: patched: Fix merged into develop branch
- 2026-06-02: disclosed: Vulnerability details published