vendor:
Qloapps
by:
Astik Rawat (ahrixia)
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Qloapps
Affected Version From: 1.5.2002
Affected Version To: 1.5.2002
Patch Exists: YES
Related CWE: CVE-2023-30256
CPE: a:webkul:qloapps:1.5.2
Tags: packetstorm,cve,cve2023,xss,webkul-qloapps,unauth
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Nuclei Metadata: {'max-request': 1, 'verified': 'true', 'vendor': 'webkul', 'product': 'qloapps'}
Platforms Tested: Kali Linux 2022.4
2023
Webkul Qloapps 1.5.2 – Cross-Site Scripting (XSS)
A Cross Site Scripting (XSS) vulnerability exists in Webkul Qloapps which is a free and open-source hotel reservation & online booking system. The vulnerability can be exploited through the 'back' and 'email_create' parameters.
Mitigation:
To mitigate this vulnerability, input validation and output encoding should be implemented to prevent malicious user input from being executed as code.