QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions. | |
| Title | QloApps through 1.7.0 Reflected XSS via List Filter Parameters | |
| First Time appeared |
Webkul
Webkul qloapps |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T01:50:33.852Z
Reserved: 2026-09-11T10:52:56.669Z
Link: CVE-2026-89268
No data.
Status : Received
Published: 2026-09-12T02:16:24.623
Modified: 2026-09-12T02:16:24.623
Link: CVE-2026-89268
No data.
OpenCVE Enrichment
No data.
Weaknesses