8.8
CVE-2026-26746
- EPSS 0.25%
- Veröffentlicht 20.02.2026 00:00:00
- Zuletzt bearbeitet 24.02.2026 20:42:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensourcepos ≫ Open Source Point Of Sale Version3.4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.482 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.