CVE-2026-25558

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.
Configurations

No configuration.

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) QloApps hasta la versión 1.7.0 contiene una vulnerabilidad de cross-site scripting almacenado en el gestor de archivos de administración que permite a los administradores autenticados inyectar JavaScript malicioso al subir archivos SVG manipulados. Los atacantes pueden incrustar controladores de eventos de JavaScript como onload dentro de archivos SVG subidos a través del gestor de archivos para ejecutar scripts arbitrarios en el navegador de cualquier usuario que vea el archivo posteriormente.

08 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 15:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-25558

Mitre link : CVE-2026-25558

CVE.ORG link : CVE-2026-25558


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')