Junglewise Threat Intelligence

CVE-2026-92234: QloApps QloApps stored XSS in Hotel Reservation System feature management

CVE-2026-92234 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Technologies: QloApps. Vendors: QloApps.

Executive brief

QloApps is a free, open-source hotel management and reservation system. A vulnerability in the Hotel Reservation System feature management page allows authenticated back-office administrators to inadvertently execute malicious code in their session via a crafted link. An attacker could use this to steal administrative credentials, modify hotel settings, or compromise guest reservations.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in the Hotel Reservation System feature management page. Unescaped child feature names are reflected directly into validation error messages displayed to back-office users, allowing an attacker to inject JavaScript via the child_features parameter. The attack requires an authenticated back-office user to visit a malicious link, but no user interaction beyond clicking the link is necessary. Exploitation allows arbitrary JavaScript execution in the context of the administrative session, potentially enabling session hijacking, credential theft, or unauthorized modifications to hotel configurations.

Affected products

  • QloApps QloApps through 1.7.0

Timeline

  • 2026-09-15: disclosed

References

Related threats