Security
Loading…

CVE-2026-89268

MEDIUMCVSS 5.4
Description

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.

Timeline
Published:September 12th, 2026 2:16 AM
Last modified:September 14th, 2026 7:17 PM
CVSS Scoring

CVSS v3: 5.4 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute