Junglewise Threat Intelligence

CVE-2026-93988: QloApps path traversal in getEmailHTML

CVE-2026-93988 · Severity: medium · CVSS 6.5 · Published 2026-09-19

Technologies: QloApps. Vendors: QloApps.

Executive brief

QloApps is a free, open-source hotel management system that handles property management, booking, and website functionality. An authenticated administrator with back-office access can exploit a path traversal vulnerability to read arbitrary files from the server, potentially exposing sensitive data such as database credentials and configuration files. This could lead to complete compromise of the hotel management system and guest data.

Technical details

A path traversal vulnerability exists in the getEmailHTML action of admin/ajax.php that fails to properly validate the email parameter. An authenticated back-office user can supply relative path sequences (such as ../) to bypass directory restrictions and read arbitrary files from the system. The vulnerability requires prior authentication but allows access to sensitive files outside the intended directory scope.

Affected products

  • Qloapps QloApps through 1.7.0

Timeline

  • 2026-09-19: disclosed

References

Related threats