QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.
References
Configurations
No configuration.
History
23 Jul 2026, 07:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-08 15:16
Updated : 2026-07-23 07:10
NVD link : CVE-2026-25558
Mitre link : CVE-2026-25558
CVE.ORG link : CVE-2026-25558
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
