Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter. | |
| Title | QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors | |
| First Time appeared |
Webkul
Webkul qloapps |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T20:56:46.515Z
Reserved: 2026-09-15T19:27:24.634Z
Link: CVE-2026-92234
No data.
Status : Received
Published: 2026-09-15T21:16:49.350
Modified: 2026-09-15T21:16:49.350
Link: CVE-2026-92234
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')