THREAT OPS › Threat News › [NVD] CVE-2026-89268 (MEDIUM 5.4) — QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executin
[NVD] CVE-2026-89268 (MEDIUM 5.4) — QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executin
CVE-2026-89268 CVSS: 5.4 MEDIUM Published: 2026-09-12T02:16:24.623
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to re
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-89268cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-89268