5.4
CVE-2026-39380
- EPSS 0.16%
- Veröffentlicht 07.04.2026 19:49:13
- Zuletzt bearbeitet 24.04.2026 17:51:06
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location parameter, allowing attackers to inject malicious JavaScript code that is stored in the database and executed when rendered in the Employees interface. This vulnerability is fixed in 3.4.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensourcepos ≫ Open Source Point Of Sale Version < 3.4.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/opensourcepos/opensourcepos/security/advisories/GHSA-7hg5-68rx-xpmg