S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-30256 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Webkil QloApps affects v. 1.5.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-30256
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Webkil QloApps v.1.5.2 is a web-based software for hotel management, enabling hoteliers to manage their daily operations including room assignments, reservations, and guest information, all in one place. The software also provides a dashboard feature to help managers monitor and analyze metrics related to bookings, occupancy rates, and revenue.

Recently, a vulnerability identified as CVE-2023-30256 has been detected in the software. This particular vulnerability allows remote attackers to obtain sensitive information simply by exploiting the "back" and "email_create" parameters in the AuthController.php file. Such information could include personally identifiable details about guests, booking information, and financial data of the hotel.

If exploited, this vulnerability can lead to significant data breaches, resulting in reputational damage to the hotel, monetary loss for the business and potentially irreversible damage to the guests' personal information. In addition, the exploitation of this vulnerability can result in regulatory sanctions and lawsuits for non-compliance with data protection laws.

By identifying and fixing this vulnerability, Webkil QloApps can restore its customers' trust, ensuring protection against future attacks. Moreover, tools such as s4e.io can help businesses uncover and secure vulnerabilities in their digital assets quickly and easily via their innovative pro-features. This ensures that businesses can take the necessary steps to protect their assets without the need for extensive cybersecurity knowledge. It is through the use of automated tools that businesses can stay one step ahead of attackers and ensure that their assets are protected against the ever-changing threat landscape.

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, hotel managers can take various proactive measures including monitoring their networks, regularly updating their software, and patching vulnerabilities as they are detected.  Here are some best practices to follow:

  • Update all software to the latest version to patch any known vulnerabilities.
  • Implement a Web Application Firewall (WAF) that blocks malicious traffic.
  • Limit external access to the system and disable unnecessary network services.
  • Train employees on basic cybersecurity principles, such as protecting passwords and reporting suspicious activity.
  • Actively monitor network activity, and establish an incident response plan.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.